CVE-2026-19586
9.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: f23511db-6c3e-4e32-a477-6aa17d310630 (Secondary)
Description
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.
Successful exploitation may allow arbitrary command execution, potentially
leading to full compromise of the affected device.
Affected (19)
Products: Tp Link: Er7212pc Firmware, Er605 Firmware, Er605w Firmware, Er7206 Firmware, Er7406 Firmware, Er707 M2 Firmware, Er7412 M2 Firmware, Er8411 Firmware, Er706w Firmware, Er706w 4g Firmware, Er706wp 4g Firmware, Er703wp 4g Outdoor Firmware, Er603wp 4g Outdoor Firmware, Er701 5g Outdoor Firmware, Dr3220v 4g Firmware, Dr3650v Firmware, Dr3650v 4g Firmware, Dr3150 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.4.3 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er7212pc | Version 2.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.4.4 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er605 | Version 2.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.4 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er605w | Version 2.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.5 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er7206 | Version 2.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.3.4 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er7406 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.4 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er707 M2 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.0 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er7412 M2 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.1 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er8411 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.11 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er706w | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.6 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er706w 4g | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.1.11 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er706w 4g | Version 2.0 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.1.11 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er706wp 4g | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.1.7 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er703wp 4g Outdoor | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.2 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er603wp 4g Outdoor | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.3 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Er701 5g Outdoor | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.0 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Dr3220v 4g | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.0 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Dr3650v | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.0 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Dr3650v 4g | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Dr3150 | All versions |
References (4)
Source: f23511db-6c3e-4e32-a477-6aa17d310630
ExploitThird Party Advisory
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Product
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Product
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Vendor Advisory
Timeline
No history available yet.