CVE-2026-75118
8.7TP-Link · TL-MR100 v3.20
The TP-Link TL-MR100 v3.20 is vulnerable to a pre-authentication stack-based buffer overflow in the http_gdpr_decrypt function, potentially allowing arbitrary code execution.
Executive summary
A critical buffer overflow vulnerability in the TP-Link TL-MR100 v3.20 router allows an adjacent unauthenticated attacker to achieve arbitrary code execution.
Vulnerability
This is a stack-based buffer overflow (CWE-121) occurring in the http_gdpr_decrypt function. An adjacent unauthenticated attacker can send malicious encrypted requests to the /cgi/login endpoint to overwrite control-flow data on the process stack.
Business impact
With a CVSS score of 8.7, this flaw poses a severe risk to network integrity. An attacker gaining arbitrary code execution on the router could intercept internal traffic, pivot to other network segments, or permanently disable the device, leading to significant security breaches and loss of network availability.
Remediation
Immediate Action: Update the firmware of the affected TL-MR100 v3.20 device to version (EU)_1.3.0 Build 260609 or later.
Proactive Monitoring: Review router management logs for repeated failed login attempts or unusual traffic patterns directed at the /cgi/login endpoint.
Compensating Controls: Restrict access to the router's web management interface to trusted management VLANs and disable remote administrative access where possible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability is highly severe because it allows unauthenticated code execution on network infrastructure. Administrators should apply the firmware update immediately and ensure that administrative interfaces are not exposed to untrusted network segments.
More TP-Link CVEs
Sources
Originally found and disclosed by Kylian Eury, per the CVE Program record.