CVE-2026-8619: TP-Link Archer MR600 Firmware
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.
Affected products
- TP-Link Archer MR600 Firmware: before 1.10.0 (fixed in 1.10.0)
- TP-Link Tl-MR100 Firmware: before 1.3.0 (fixed in 1.3.0)
- TP-Link Tl-MR150 Firmware: before 1.3.0 (fixed in 1.3.0)
- TP-Link Tl-MR6400 Firmware: before 1.5.0 (fixed in 1.5.0)
Published 2026-08-20. Last modified 2026-09-03.