VYPR

TL-MR6400

by TP-Link

CVEs (8)

  • CVE-2026-3841HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.02

    A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during specific CLI operations. An authenticated attacker with elevated privileges…

  • CVE-2026-17250HigAug 21, 2026
    risk 0.55cvss —epss 0.00

    A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlled metadata within a firmware image. Successful exploitation may allow an authenticated attacker to trigger memory…

  • CVE-2026-8619HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference.  A remote attacker on an…

  • CVE-2026-17252HigAug 21, 2026
    risk 0.46cvss —epss 0.00

    A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability by sending a specially crafted malformed…

  • CVE-2026-17251HigAug 21, 2026
    risk 0.46cvss —epss 0.00

    A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of  TL-MR6400 v7. An unauthenticated remote attacker can trigger the vulnerability by sending a specially crafted HTTP request containing a malformed session cookie header. …

  • CVE-2026-12339MedAug 10, 2026
    risk 0.45cvss —epss 0.00

    A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file…

  • CVE-2026-76653MedSep 10, 2026
    risk 0.34cvss —epss 0.00

    A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information…

  • CVE-2026-76652MedSep 10, 2026
    risk 0.31cvss —epss 0.01

    An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected…