HIGHVulnerability
CVE-2026-8619
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.
Properties
- severity
- HIGH
- score
- 7.5
- epss_score
- 0.00442
- cve_id
- CVE-2026-8619
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- published_at
- 2026-08-20T00:16:53.157
- last_modified
- 2026-09-03T15:04:30.077
- epss_percentile
- 0.37005
Related Entities (11)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]NULL Pointer Dereference
DESCRIBED_BY (1)
→[Source]NVD
AFFECTS_PRODUCT (8)
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
Explore deeper with Ninja Signal's threat intelligence graph