SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-8619

HIGH · CVSS 7.5 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-11

CyberRota Analysis

AI-Generated

TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0, and Archer MR600 v2 devices are vulnerable to an unauthenticated denial-of-service attack due to improper handling of exceptional request conditions, leading to a NULL pointer dereference. A remote attacker on an adjacent network can exploit this vulnerability by sending a specially crafted HTTP request, causing the HTTP service to crash and rendering the web management interface and HTTP-dependent functionalities temporarily unavailable. Organizations using these devices should prioritize patching to mitigate the risk of service disruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-8619
Severity
HIGH
CVSS
7.5
EPSS
0.44%

Original NVD Description

An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference.  A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.

Related CVEs

Other vulnerabilities affecting the same vendor(s)