VYPR

TL-MR100

by TP-Link

CVEs (2)

  • CVE-2026-75118HigAug 28, 2026
    risk 0.57cvss —epss 0.00

    A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to the /cgi/login endpoint. An adjacent unauthenticated attacker with access to the router's web…

  • CVE-2026-8619HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference.  A remote attacker on an…