GHSA-cfmx-mjrq-52xjHigh

A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of  TL...

Published
August 21, 2026
Last Modified
August 21, 2026

🔗 CVE IDs covered (1)

📋 Description

A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of  TL-MR6400 v7. An unauthenticated remote attacker can trigger the vulnerability by sending a specially crafted HTTP request containing a malformed session cookie header.

Successful exploitation may cause the HTTP service process to crash, resulting in a denial-of-service condition and temporary loss of management or CGI functionality until service recovery.

🔗 References (5)