← Back

CVE-2026-19683

nvd nist
Published: Aug 20, 2026Modified: Sep 8, 2026

JSON object

Loading...
6.3
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: f23511db-6c3e-4e32-a477-6aa17d310630 (Secondary)

Description

A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path.  Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.

Affected (19)

18 products
Er7212pc Firmware
Er605 Firmware
Er7206 Firmware
Er7406 Firmware
Er707 M2 Firmware
Er7412 M2 Firmware
Er8411 Firmware
Er706w Firmware
Er706w 4g Firmware
Er706wp 4g Firmware
Er703wp 4g Outdoor Firmware
Dr3220v 4g Firmware
Dr3650v Firmware
Dr3650v 4g Firmware
Er603wp 4g Outdoor Firmware
Dr3150 Firmware
Er701 5g Outdoor Firmware
Er605w Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.4.3
Running on/withPlatform Versions
Tp Link
Er7212pc
Version 2.0
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.4.4
Running on/withPlatform Versions
Tp Link
Er605
Version 2.0
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.3.5
Running on/withPlatform Versions
Tp Link
Er7206
Version 2.0
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.3.4
Running on/withPlatform Versions
Tp Link
Er7406
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.4
Running on/withPlatform Versions
Tp Link
Er707 M2
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0
Running on/withPlatform Versions
Tp Link
Er7412 M2
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.1
Running on/withPlatform Versions
Tp Link
Er8411
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.11
Running on/withPlatform Versions
Tp Link
Er706w
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.6
Running on/withPlatform Versions
Tp Link
Er706w 4g
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.1.11
Running on/withPlatform Versions
Tp Link
Er706w 4g
Version 2.0
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.11
Running on/withPlatform Versions
Tp Link
Er706wp 4g
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.7
Running on/withPlatform Versions
Tp Link
Er703wp 4g Outdoor
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0
Running on/withPlatform Versions
Tp Link
Dr3220v 4g
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0
Running on/withPlatform Versions
Tp Link
Dr3650v
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0
Running on/withPlatform Versions
Tp Link
Dr3650v 4g
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.2
Running on/withPlatform Versions
Tp Link
Er603wp 4g Outdoor
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.1
Running on/withPlatform Versions
Tp Link
Dr3150
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.3
Running on/withPlatform Versions
Tp Link
Er701 5g Outdoor
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.0.4
Running on/withPlatform Versions
Tp Link
Er605w
Version 2.0

References (3)

Source: f23511db-6c3e-4e32-a477-6aa17d310630
Product
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Product
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Vendor Advisory

Timeline

No history available yet.