CVE-2026-19586
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt. Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.7% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2026-08-20 |
| Last modified | 2026-09-03 |
Affected (36)
| Vendor | Product |
|---|---|
| tp-link | dr3150 |
| tp-link | dr3150 firmware |
| tp-link | dr3220v-4g |
| tp-link | dr3220v-4g firmware |
| tp-link | dr3650v |
| tp-link | dr3650v firmware |
| tp-link | dr3650v-4g |
| tp-link | dr3650v-4g firmware |
| tp-link | er603wp-4g-outdoor |
| tp-link | er603wp-4g-outdoor firmware |
| tp-link | er605 |
| tp-link | er605 firmware |
| tp-link | er605w |
| tp-link | er605w firmware |
| tp-link | er701-5g-outdoor |
| tp-link | er701-5g-outdoor firmware |
| tp-link | er703wp-4g-outdoor |
| tp-link | er703wp-4g-outdoor firmware |
| tp-link | er706w |
| tp-link | er706w firmware |
| tp-link | er706w-4g |
| tp-link | er706w-4g firmware |
| tp-link | er706wp-4g |
| tp-link | er706wp-4g firmware |
| tp-link | er707-m2 |
| tp-link | er707-m2 firmware |
| tp-link | er7206 |
| tp-link | er7206 firmware |
| tp-link | er7212pc |
| tp-link | er7212pc firmware |
| tp-link | er7406 |
| tp-link | er7406 firmware |
| tp-link | er7412-m2 |
| tp-link | er7412-m2 firmware |
| tp-link | er8411 |
| tp-link | er8411 firmware |
References
→ the Explorer · watch your stack · NVD