← Back

CVE-2026-19586

nvd nist
Published: Aug 20, 2026Modified: Sep 3, 2026

JSON object

Loading...
9.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: f23511db-6c3e-4e32-a477-6aa17d310630 (Secondary)

Description

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.  Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.

Affected (19)

18 products
Er7212pc Firmware
Er605 Firmware
Er605w Firmware
Er7206 Firmware
Er7406 Firmware
Er707 M2 Firmware
Er7412 M2 Firmware
Er8411 Firmware
Er706w Firmware
Er706w 4g Firmware
Er706wp 4g Firmware
Er703wp 4g Outdoor Firmware
Er603wp 4g Outdoor Firmware
Er701 5g Outdoor Firmware
Dr3220v 4g Firmware
Dr3650v Firmware
Dr3650v 4g Firmware
Dr3150 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.4.3
Running on/withPlatform Versions
Tp Link
Er7212pc
Version 2.0
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.4.4
Running on/withPlatform Versions
Tp Link
Er605
Version 2.0
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.0.4
Running on/withPlatform Versions
Tp Link
Er605w
Version 2.0
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.3.5
Running on/withPlatform Versions
Tp Link
Er7206
Version 2.0
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.3.4
Running on/withPlatform Versions
Tp Link
Er7406
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.4
Running on/withPlatform Versions
Tp Link
Er707 M2
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0
Running on/withPlatform Versions
Tp Link
Er7412 M2
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.1
Running on/withPlatform Versions
Tp Link
Er8411
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.11
Running on/withPlatform Versions
Tp Link
Er706w
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.6
Running on/withPlatform Versions
Tp Link
Er706w 4g
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.1.11
Running on/withPlatform Versions
Tp Link
Er706w 4g
Version 2.0
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.11
Running on/withPlatform Versions
Tp Link
Er706wp 4g
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.7
Running on/withPlatform Versions
Tp Link
Er703wp 4g Outdoor
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.2
Running on/withPlatform Versions
Tp Link
Er603wp 4g Outdoor
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.3
Running on/withPlatform Versions
Tp Link
Er701 5g Outdoor
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0
Running on/withPlatform Versions
Tp Link
Dr3220v 4g
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0
Running on/withPlatform Versions
Tp Link
Dr3650v
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0
Running on/withPlatform Versions
Tp Link
Dr3650v 4g
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.1
Running on/withPlatform Versions
Tp Link
Dr3150
All versions

References (4)

Source: f23511db-6c3e-4e32-a477-6aa17d310630
ExploitThird Party Advisory
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Product
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Product
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Vendor Advisory

Timeline

No history available yet.