7.4
CVE-2026-19683
- EPSS -
- Veröffentlicht 20.08.2026 18:32:27
- Zuletzt bearbeitet 08.09.2026 20:46:03
- Erkennungen
Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada Gateways
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path. Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Er7212pc Firmware Version < 2.4.3
Tp-link ≫ Er605 Firmware Version < 2.4.4
Tp-link ≫ Er7206 Firmware Version < 2.3.5
Tp-link ≫ Er7406 Firmware Version < 1.3.4
Tp-link ≫ Er707-m2 Firmware Version < 1.4.4
Tp-link ≫ Er7412-m2 Firmware Version < 1.2.0
Tp-link ≫ Er8411 Firmware Version < 1.4.1
Tp-link ≫ Er706w Firmware Version < 1.2.11
Tp-link ≫ Er706w-4g Firmware Version < 1.2.6
Tp-link ≫ Er706w-4g Firmware Version < 2.1.11
Tp-link ≫ Er706wp-4g Firmware Version < 1.1.11
Tp-link ≫ Er703wp-4g-outdoor Firmware Version < 1.1.7
Tp-link ≫ Dr3220v-4g Firmware Version < 1.2.0
Tp-link ≫ Dr3650v Firmware Version < 1.2.0
Tp-link ≫ Dr3650v-4g Firmware Version < 1.2.0
Tp-link ≫ Er603wp-4g-outdoor Firmware Version < 1.0.2
Tp-link ≫ Dr3150 Firmware Version < 1.0.1
Tp-link ≫ Er701-5g-outdoor Firmware Version < 1.0.3
Tp-link ≫ Er605w Firmware Version < 2.0.4
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| f23511db-6c3e-4e32-a477-6aa17d310630 | 6.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
https://www.omadanetworks.com/us/support/download/
https://www.omadanetworks.com/en/support/download/
https://www.tp-link.com/us/support/faq/5256/