A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
After logging into the web portal administrative panel, an attacker can provide specially crafted input data that is not properly validated or sanitized (CWE-78). This results in passing untrusted data directly to the device's system command interpreter. The exploit therefore requires possession of administrator credentials or takeover of an active administrative session.
An attacker with administrator privileges can execute arbitrary system commands on the device, which may lead to complete takeover of the gateway, loss of data confidentiality and integrity, and disruption of network availability served by the device.
Apply patches available from the manufacturer according to references (including https://support.omadanetworks.com/en/document/108456/). Until the update is applied, it is recommended to restrict access to the administrative panel only to trusted hosts and avoid exposing the management interface to the public network.
TP-Link FR307-M2 Firmware, TP-Link G36, TP-Link ER707-M2, TP-Link ER706W Firmware, TP-Link ER7206 Firmware (Omada series gateways); specific firmware versions indicated in manufacturer references.
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XTp Link Er605
HWTp-Linkall versionsTp Link Er605 Firmware
OSTp-Link2.3.1< 2.3.1Tp Link Er706w
HWTp-Linkall versionsTp Link Er706w 4g
HWTp-Linkall versionsTp Link Er706w 4g Firmware
OSTp-Link1.2.1< 1.2.1Tp Link Er706w Firmware
OSTp-Link1.2.1< 1.2.1Tp Link Er707 M2
HWTp-Linkall versionsTp Link Er707 M2 Firmware
OSTp-Link1.3.1< 1.3.1Tp Link Er7206
HWTp-Linkall versionsTp Link Er7206 Firmware
OSTp-Link2.2.2< 2.2.2Tp Link Er7212pc
HWTp-Linkall versionsTp Link Er7212pc Firmware
OSTp-Link2.1.3< 2.1.3Tp Link Er7412 M2
HWTp-Linkall versionsTp Link Er7412 M2 Firmware
OSTp-Link1.1.0< 1.1.0Tp Link Er8411
HWTp-Linkall versionsTp Link Er8411 Firmware
OSTp-Link1.3.3< 1.3.3Tp Link Fr205
HWTp-Linkall versionsTp Link Fr205 Firmware
OSTp-Link1.0.3< 1.0.3Tp Link Fr307 M2
HWTp-Linkall versionsTp Link Fr307 M2 Firmware
OSTp-Link1.2.5< 1.2.5Tp Link Fr365
HWTp-Linkall versionsTp Link Fr365 Firmware
OSTp-Link1.1.10< 1.1.10Tp Link G36
HWTp-Linkall versionsTp Link G36 Firmware
OSTp-Link1.1.4< 1.1.4Tp Link G611
HWTp-Linkall versionsTp Link G611 Firmware
OSTp-Link1.2.2< 1.2.2
Related vulnerabilities
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to op...
Zdalne wykonanie poleceń OS bez uwierzytelnienia w routerach TP-Link Omada
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gate...
An arbitrary OS command may be executed on the product by the user who can log in to the web management interf...
A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigab...