ZeroHour

CVE-2026-75118

large

Pre-auth Stack Buffer Overflow in TP-Link TL-MR100 V3.20 Web Interface

CVSS 4.0
8.7 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-75118 is a pre-authentication stack-based buffer overflow (CWE-121) in the http_gdpr_decrypt function of the web server on the TP-Link TL-MR100 router running V3.20. An adjacent, unauthenticated attacker who can reach the router's web management interface can send a crafted encrypted request to the /cgi/login endpoint, where insufficient bounds checking lets data overflow a stack buffer and overwrite saved control-flow data on the httpd process stack. Successful exploitation can crash the httpd service or potentially achieve arbitrary code execution in the context of that process, with high impact on confidentiality, integrity, and availability (CVSS 4.0 score 8.7). Only TL-MR100 units on the affected V3.20 firmware whose management interface is reachable from an adjacent network (e.g., untrusted LAN users or WAN-side management) are at risk. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates a 0.3% probability of exploitation within 30 days.

What to do: Check the hardware/firmware version of your TL-MR100 in the web management interface and update to the latest TP-Link firmware for the device once a fixed release is published (no fixed version is specified in the available data). Until patched, restrict access to the web management interface to trusted LAN clients, disable WAN-side or remote management if enabled, and prevent untrusted devices from reaching /cgi/login.

Affected
TP-Link TL-MR100V3.20 (the only version named in the advisory; no other affected or fixed version ranges are provided in the available data)
Estimated exposure
largeplausibly on the order of hundreds of thousands of deployed TL-MR100 V3.20 units (estimate) — TP-Link is among the largest consumer router vendors by unit shipments and the TL-MR100 is a low-cost, globally sold 4G LTE model, so the installed base for a single hardware/firmware line is plausibly in the hundreds of thousands, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to the /cgi/login endpoint. An adjacent unauthenticated attacker with access to the router's web management interface can trigger memory corruption and potentially achieve arbitrary code execution. Successful exploitation can overwrite saved control-flow data on the httpd process stack prior to authentication, resulting in a service crash or potential arbitrary code execution in the context of the affected process.

Weakness
CWE-121
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.