CRITICAL🇬🇧 English

CVE-2026-19586

CVSS 9.3v4.0pub. 2026-08-20upd. 2026-09-03

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.  Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.

oryginał EN
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Tp Link Dr3150

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Dr3150 Firmware

    OS
    Tp-Link
    < 1.0.1
  • Tp Link Dr3220v 4g

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Dr3220v 4g Firmware

    OS
    Tp-Link
    < 1.2.0
  • Tp Link Dr3650v

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Dr3650v 4g

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Dr3650v 4g Firmware

    OS
    Tp-Link
    < 1.2.0
  • Tp Link Dr3650v Firmware

    OS
    Tp-Link
    < 1.2.0
  • Tp Link Er603wp 4g Outdoor

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Er603wp 4g Outdoor Firmware

    OS
    Tp-Link
    < 1.0.2
  • Tp Link Er605

    HW
    Tp-Link
    2.0
  • Tp Link Er605 Firmware

    OS
    Tp-Link
    < 2.4.4
  • Tp Link Er605w

    HW
    Tp-Link
    2.0
  • Tp Link Er605w Firmware

    OS
    Tp-Link
    < 2.0.4
  • Tp Link Er701 5g Outdoor

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Er701 5g Outdoor Firmware

    OS
    Tp-Link
    < 1.0.3
  • Tp Link Er703wp 4g Outdoor

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Er703wp 4g Outdoor Firmware

    OS
    Tp-Link
    < 1.1.7
  • Tp Link Er706w

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Er706w 4g

    HW
    Tp-Link
    2.0
  • Tp Link Er706w 4g Firmware

    OS
    Tp-Link
    < 2.1.11< 1.2.6
  • Tp Link Er706w Firmware

    OS
    Tp-Link
    < 1.2.11
  • Tp Link Er706wp 4g

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Er706wp 4g Firmware

    OS
    Tp-Link
    < 1.1.11
  • Tp Link Er707 M2

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Er707 M2 Firmware

    OS
    Tp-Link
    < 1.4.4
  • Tp Link Er7206

    HW
    Tp-Link
    2.0
  • Tp Link Er7206 Firmware

    OS
    Tp-Link
    < 2.3.5
  • Tp Link Er7212pc

    HW
    Tp-Link
    2.0
  • Tp Link Er7212pc Firmware

    OS
    Tp-Link
    < 2.4.3
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
VPNCommand Injection
CWE
Referencje

Powiązane podatności

CVE-2025-6542CRITICAL9.3PL ✓ten sam produkt

Zdalne wykonanie poleceń OS bez uwierzytelnienia w routerach TP-Link Omada

CVE-2025-7850CRITICAL9.3PL ✓ten sam produkt

Command injection w bramkach Omada (TP-Link) po uwierzytelnieniu admina

CVE-2025-7851HIGH8.7ten sam produkt

An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gate...

CVE-2025-6541HIGH8.6ten sam produkt

An arbitrary OS command may be executed on the product by the user who can log in to the web management interf...

CVE-2024-21827HIGH7.2ten sam produkt

A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigab...