stack-based buffer overflow vulnerability exists in the firmware update
functionality of TL-MR6400 v7 due to unsafe processing of
attacker-controlled metadata within a firmware image.
Successful
exploitation may allow an authenticated attacker to trigger memory corruption
and execute arbitrary code on the affected device.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link tl-mr6400 V7 |
|
| Vendors & Products |
Tp-link
Tp-link tl-mr6400 V7 |
Fri, 21 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlled metadata within a firmware image. Successful exploitation may allow an authenticated attacker to trigger memory corruption and execute arbitrary code on the affected device. | |
| Title | Authenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update Handling | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-08-21T17:41:01.254Z
Reserved: 2026-07-24T22:03:10.608Z
Link: CVE-2026-17250
Updated: 2026-08-21T17:40:55.960Z
Status : Received
Published: 2026-08-21T18:16:47.450
Modified: 2026-08-21T18:16:47.450
Link: CVE-2026-17250
No data.
OpenCVE Enrichment
Updated: 2026-08-21T21:15:23Z