{"id":"CVE-2026-75118","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-75118","summary":"A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to…","details":"A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to the /cgi/login endpoint. An adjacent unauthenticated attacker with access to the router's web management interface can trigger memory corruption and potentially achieve arbitrary code execution.\n\n\n\n\n\n\n\nSuccessful exploitation can overwrite saved control-flow data on the httpd process stack prior to authentication, resulting in a service crash or potential arbitrary code execution in the context of the affected process.","published":"2026-08-28T22:16:52.880","modified":"2026-08-28T22:16:52.880","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.tp-link.com/en/support/download/tl-mr100/v3.20/#Firmware"},{"type":"WEB","url":"https://www.tp-link.com/en/support/faq/5271/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T22:16:52.880"}}