Description
A
stack-based buffer overflow vulnerability exists in the firmware update
functionality of TL-MR6400 v7 due to unsafe processing of
attacker-controlled metadata within a firmware image.





Successful
exploitation may allow an authenticated attacker to trigger memory corruption
and execute arbitrary code on the affected device.
Published: 2026-08-21
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlled metadata within a firmware image. Successful exploitation may allow an authenticated attacker to trigger memory corruption and execute arbitrary code on the affected device.
Title Authenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmware Update Handling
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-21T17:41:01.254Z

Reserved: 2026-07-24T22:03:10.608Z

Link: CVE-2026-17250

cve-icon Vulnrichment

Updated: 2026-08-21T17:40:55.960Z

cve-icon NVD

Status : Received

Published: 2026-08-21T18:16:47.450

Modified: 2026-08-21T18:16:47.450

Link: CVE-2026-17250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses