Skip to finding
important · Wi-Fi

An unauthenticated TL-MR100 LAN request can overwrite saved control-flow data in httpd.

Affects

TP-Link TL-MR100 V3.20, an embedded 4G LTE Wi-Fi router.

A crafted encrypted request to /cgi/login triggers a stack overflow before authentication and overwrites saved control-flow data.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 4, 2026