The TP-Link TL-MR6400, a 4G LTE router designed for mobile connectivity and areas without fixed coverage, has been affected by three high-severity vulnerabilities that allow attackers to execute arbitrary code or crash the device. Hardware version 7 of the router is impacted, and TP-Link has released a patch available as firmware 1.9.0 Build 260714.

Add AlexTech.ai asPreferred Source on Google

Three CVEs with distinct network impacts

The vulnerabilities, identified as CVE-2026-17250, CVE-2026-17251, and CVE-2026-17252, carry a maximum CVSSv4 score of 8.5. The most critical flaw, CVE-2026-17250, is a stack-based buffer overflow triggered when an authenticated user uploads a firmware image with malicious metadata: the router mishandles this data, leading to memory corruption and code execution. CVE-2026-17251 is a null pointer dereference exploitable by an unauthenticated attacker sending an HTTP request with a malformed session cookie, causing the immediate crash of the HTTP service. Finally, CVE-2026-17252 is an out-of-bounds write vulnerability activatable by an adjacent attacker sending a malformed HTTP request to the login interface, crashing the web management service.

TL-MR6400 | Router 4G LTE Inalámbrico N a 300Mbps | TP-Link España — https://www.tp-link.com/es/home-networking/3g-4g-router/tl-mr6400/

Immediate update required to prevent full network control

No active exploitation in the wild has been confirmed, but the ability to gain full control of the router or take it offline represents a significant risk to network integrity and connected devices. Network administrators must prioritize installing firmware 1.9.0 Build 260714 to mitigate these risks. This incident fits into a broader context of router vulnerabilities, as highlighted by previous attacks on TP-Link and D-Link devices and security issues in Acer mesh routers, underscoring the importance of keeping peripheral devices updated.

TP-Link TL-MR6400 4G LTE Router - mit Zubehör (Gebraucht) in Birsfelden ... — https://www.ricardo.ch/de/a/tp-link-tl-mr6400-4g-lte-router-mit-zubehoer-1305994774/

Impact on mobile connection security

4G routers like the TL-MR6400 are often used in contexts where network security is less monitored than traditional enterprise infrastructure. The presence of flaws allowing remote code execution or denial-of-service attacks makes these devices attractive targets for botnets and DDoS attacks. Firmware updates are not just routine maintenance but a crucial step to protect the network from compromises that could extend to all connected devices.