CVE-2026-19683
- EPSS -
- Veröffentlicht 20.08.2026 18:32:27
- Zuletzt bearbeitet 08.09.2026 20:46:03
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or man...
CVE-2026-19586
- EPSS -
- Veröffentlicht 20.08.2026 18:32:06
- Zuletzt bearbeitet 03.09.2026 15:05:12
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticate...
CVE-2026-9033
- EPSS -
- Veröffentlicht 20.08.2026 18:31:54
- Zuletzt bearbeitet 08.09.2026 20:41:37
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authe...
CVE-2025-9290
- EPSS 0.2%
- Veröffentlicht 22.01.2026 23:14:45
- Zuletzt bearbeitet 07.10.2026 00:17:19
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept a...
CVE-2025-7851
- EPSS 0.62%
- Veröffentlicht 21.10.2025 00:29:05
- Zuletzt bearbeitet 24.10.2025 17:15:43
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
CVE-2025-7850
- EPSS 1.95%
- Veröffentlicht 21.10.2025 00:28:11
- Zuletzt bearbeitet 24.10.2025 17:15:43
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
CVE-2025-6542
- EPSS 0.95%
- Veröffentlicht 21.10.2025 00:23:08
- Zuletzt bearbeitet 24.10.2025 13:50:10
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
CVE-2025-6541
- EPSS 0.66%
- Veröffentlicht 21.10.2025 00:21:42
- Zuletzt bearbeitet 24.10.2025 13:45:38
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
CVE-2024-21827
- EPSS 0.87%
- Veröffentlicht 25.06.2024 14:15:10
- Zuletzt bearbeitet 04.11.2025 18:15:50
A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An att...
CVE-2023-47618
- EPSS 1.94%
- Veröffentlicht 06.02.2024 17:15:10
- Zuletzt bearbeitet 04.11.2025 19:16:06
A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An at...