PT-2026-83352 · Tp Link · Tl-Mr100

·

CVE-2026-75118

·

Published

2026-08-28

·

Updated

2026-09-01

CVSS v4.0

8.7

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions TL-MR100 version 3.20
Description A pre-authentication stack-based buffer overflow occurs in the http gdpr decrypt() function due to insufficient bounds checking of encrypted requests. An adjacent unauthenticated attacker with access to the web management interface can target the '/cgi/login' endpoint to trigger memory corruption. This can overwrite saved control-flow data on the httpd process stack, leading to a service crash or arbitrary code execution in the context of the affected process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75118

Affected Products

Tl-Mr100