Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-17251

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-476 Desreferencia a puntero nulo (NULL)
Fecha de publicación:
21/08/2026
Última modificación:
21/08/2026

Descripción

*** Pendiente de traducción *** A NULL<br /> pointer dereference vulnerability exists in the HTTP request parsing<br /> functionality of <br /> TL-MR6400 v7. An unauthenticated remote attacker can<br /> trigger the vulnerability by sending a specially crafted HTTP request<br /> containing a malformed session cookie header. <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may cause the HTTP service process to crash, resulting in a<br /> denial-of-service condition and temporary loss of management or CGI<br /> functionality until service recovery.