← Back

Er7206 Firmware

er7206_firmware

Vendor: Tp Link • 14 CVEs

CVEs (14)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
56Beam Bridge 5 Ur Firmware
Dr3220v 4g FirmwareDr3650v 4g Firmware+53 more
Jun 17, 2026
Jan 23, 2026
6.0 MEDIUM· v4
5.9 MEDIUM· v3
N/A· v2
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and all...Show more
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.Show less
1Tp Link
13Er605 Firmware
Er706w 4g FirmwareEr706w Firmware+10 more
Jun 17, 2026
Oct 21, 2025
8.7 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
1Tp Link
13Er605 Firmware
Er706w 4g FirmwareEr706w Firmware+10 more
Jun 17, 2026
Oct 21, 2025
9.3 CRITICAL· v4
7.2 HIGH· v3
N/A· v2
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
1Tp Link
13Er605 Firmware
Er706w 4g FirmwareEr706w Firmware+10 more
Jun 17, 2026
Oct 21, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
1Tp Link
13Er605 Firmware
Er706w 4g FirmwareEr706w Firmware+10 more
Jun 17, 2026
Oct 21, 2025
8.6 HIGH· v4
8.8 HIGH· v3
N/A· v2
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Jun 25, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbit...Show more
A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.Show less
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbi...Show more
A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to a...Show more
A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbit...Show more
A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitra...Show more
A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request c...Show more
A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection . An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execu...Show more
A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can l...Show more
A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Tp Link
1Er7206 Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitr...Show more
A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability and gain access to an unrestricted shell.Show less