TP-Link: Eight Vulnerabilities Disclosed, High-Severity Flaws Hit TL-MR6400 v7 Router
Key findings • Eight vulnerabilities disclosed across TP-Link products between August 18-21, 2026. • Multiple High-severity flaws found in TL-MR6400 v7 router, including code execution and Do…

Key findings
- Eight vulnerabilities disclosed across TP-Link products between August 18-21, 2026.
- Multiple High-severity flaws found in TL-MR6400 v7 router, including code execution and DoS.
- Vulnerabilities affect routers, gateways, and smart cameras, impacting diverse TP-Link users.
- Flaws include buffer overflows, command injection, and unencrypted credential transmission.
- Users urged to monitor for firmware updates and consult TP-Link security advisories.
On August 18-21, 2026, a batch of eight vulnerabilities was disclosed across several TP-Link product lines, with a notable cluster of high-severity flaws affecting the TL-MR6400 v7 router. These vulnerabilities, ranging from stack-based buffer overflows to null pointer dereferences and OS command injection, highlight significant security weaknesses in the affected devices. The disclosures span multiple product families, including routers, gateways, and smart cameras, indicating a broad impact for TP-Link users.
Several high-severity vulnerabilities were identified in the TP-Link TL-MR6400 v7 router. CVE-2026-17252 and CVE-2026-17251, both rated High, involve a stack-based out-of-bounds write and a NULL pointer dereference in the login request handling and HTTP request parsing, respectively. These can be exploited by unauthenticated adjacent attackers sending malformed HTTP requests. Additionally, CVE-2026-17250, also High severity, is a stack-based buffer overflow in the firmware update functionality, which could allow an authenticated attacker to execute arbitrary code.
Other high-severity issues were found in different TP-Link devices. CVE-2026-8619, a High severity denial-of-service vulnerability, affects multiple router models (TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0, and Archer MR600 v2) due to improper handling of exceptional HTTP requests. In the Archer C20 v6, CVE-2026-75616 presents an OS command injection vulnerability in the web management interface, allowing authenticated administrators to execute arbitrary system commands. For smart cameras, CVE-2026-75618 (Tapo C100/C101 V5) is a null pointer dereference in the RTSP service, potentially causing a service crash and device reboot. CVE-2026-15315 (Tapo C200 v5) is an improper authentication vulnerability allowing local network attackers to bypass controls and obtain administrative session tokens.
A medium-severity vulnerability, CVE-2026-19683, was disclosed in TP-Link Omada Gateways. This flaw affects the Dynamic DNS (DDNS) functionality, where authentication credentials are sent over an unencrypted channel, potentially exposing sensitive information to attackers observing or manipulating traffic.
Details regarding patches and affected versions were not extensively provided in the initial disclosures. However, the vulnerabilities collectively impact a range of TP-Link devices, emphasizing the need for users to stay informed about specific firmware updates and security advisories from TP-Link. The broad nature of these disclosures across different product lines suggests a comprehensive review of security practices may be warranted by the vendor.
Users of the affected TP-Link devices are advised to monitor for firmware updates and apply them as soon as they become available. The presence of multiple high-severity flaws, including those allowing arbitrary code execution and command injection, underscores the critical importance of timely patching to mitigate potential risks. The disclosure window spanning three days indicates a coordinated release of security information by the reporting parties.
The vulnerabilities disclosed in this batch include:
- Authentication Bypass & Code Execution: CVE-2026-15315, CVE-2026-17250, CVE-2026-75616
- Denial of Service: CVE-2026-17251, CVE-2026-8619, CVE-2026-75618
- Information Disclosure: CVE-2026-19683
- Buffer Overflow: CVE-2026-17252
This batch of vulnerabilities underscores the importance of regular security audits and timely patching for network devices. Users should consult TP-Link's official security advisories for the most up-to-date information on affected products and available patches. The variety of vulnerabilities and affected product lines highlights a need for vigilance among TP-Link customers.