CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Tp Link 18Dr3150 Firmware Dr3220v 4g FirmwareDr3650v 4g Firmware+15 moreSep 8, 2026 Aug 20, 2026 6.0 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions...Show more |
1Tp Link 18Dr3150 Firmware Dr3220v 4g FirmwareDr3650v 4g Firmware+15 moreSep 8, 2026 Aug 20, 2026 6.3 MEDIUM· v4 7.4 HIGH· v3 N/A· v2 A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An a...Show more |
1Tp Link 18Dr3150 Firmware Dr3220v 4g FirmwareDr3650v 4g Firmware+15 moreSep 3, 2026 Aug 20, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection es...Show more |
1Tp Link 56Beam Bridge 5 Ur Firmware Dr3220v 4g FirmwareDr3650v 4g Firmware+53 moreJun 17, 2026 Jan 23, 2026 6.0 MEDIUM· v4 5.9 MEDIUM· v3 N/A· v2 An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and all...Show more |
1Tp Link 13Er605 Firmware Er706w 4g FirmwareEr706w Firmware+10 moreJun 17, 2026 Oct 21, 2025 8.7 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. |
1Tp Link 13Er605 Firmware Er706w 4g FirmwareEr706w Firmware+10 moreJun 17, 2026 Oct 21, 2025 9.3 CRITICAL· v4 7.2 HIGH· v3 N/A· v2 A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. |
1Tp Link 13Er605 Firmware Er706w 4g FirmwareEr706w Firmware+10 moreJun 17, 2026 Oct 21, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 An arbitrary OS command may be executed on the product by a remote unauthenticated attacker. |
1Tp Link 13Er605 Firmware Er706w 4g FirmwareEr706w Firmware+10 moreJun 17, 2026 Oct 21, 2025 8.6 HIGH· v4 8.8 HIGH· v3 N/A· v2 An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. |