CVE-2026-75118
largePre-auth Stack Buffer Overflow in TP-Link TL-MR100 V3.20 Web Interface
CVE-2026-75118 is a pre-authentication stack-based buffer overflow (CWE-121) in the http_gdpr_decrypt function of the web server on the TP-Link TL-MR100 router running V3.20. An adjacent, unauthenticated attacker who can reach the router's web management interface can send a crafted encrypted request to the /cgi/login endpoint, where insufficient bounds checking lets data overflow a stack buffer and overwrite saved control-flow data on the httpd process stack. Successful exploitation can crash the httpd service or potentially achieve arbitrary code execution in the context of that process, with high impact on confidentiality, integrity, and availability (CVSS 4.0 score 8.7). Only TL-MR100 units on the affected V3.20 firmware whose management interface is reachable from an adjacent network (e.g., untrusted LAN users or WAN-side management) are at risk. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates a 0.3% probability of exploitation within 30 days.
What to do: Check the hardware/firmware version of your TL-MR100 in the web management interface and update to the latest TP-Link firmware for the device once a fixed release is published (no fixed version is specified in the available data). Until patched, restrict access to the web management interface to trusted LAN clients, disable WAN-side or remote management if enabled, and prevent untrusted devices from reaching /cgi/login.
| TP-Link TL-MR100 | V3.20 (the only version named in the advisory; no other affected or fixed version ranges are provided in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to the /cgi/login endpoint. An adjacent unauthenticated attacker with access to the router's web management interface can trigger memory corruption and potentially achieve arbitrary code execution. Successful exploitation can overwrite saved control-flow data on the httpd process stack prior to authentication, resulting in a service crash or potential arbitrary code execution in the context of the affected process.
- Weakness
- CWE-121
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.