Tp Link · Tl-Mr100 · CVE-2026-75118
**Name of the Vulnerable Software and Affected Versions**
TL-MR100 version 3.20
**Description**
A pre-authentication stack-based buffer overflow occurs in the `http gdpr decrypt()` function due to insufficient bounds checking of encrypted requests. An adjacent unauthenticated attacker with access to the web management interface can target the '/cgi/login' endpoint to trigger memory corruption. This can overwrite saved control-flow data on the httpd process stack, leading to a service crash or arbitrary code execution in the context of the affected process.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.