peter bassill · operator
$ cve CVE-2026-19586 JSON

CVE-2026-19586

9.8
CRITICAL · CVSS 3.1 · EPSS 5.7% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.  Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.7% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2026-08-20
Last modified2026-09-03

Affected (36)

VendorProduct
tp-linkdr3150
tp-linkdr3150 firmware
tp-linkdr3220v-4g
tp-linkdr3220v-4g firmware
tp-linkdr3650v
tp-linkdr3650v firmware
tp-linkdr3650v-4g
tp-linkdr3650v-4g firmware
tp-linker603wp-4g-outdoor
tp-linker603wp-4g-outdoor firmware
tp-linker605
tp-linker605 firmware
tp-linker605w
tp-linker605w firmware
tp-linker701-5g-outdoor
tp-linker701-5g-outdoor firmware
tp-linker703wp-4g-outdoor
tp-linker703wp-4g-outdoor firmware
tp-linker706w
tp-linker706w firmware
tp-linker706w-4g
tp-linker706w-4g firmware
tp-linker706wp-4g
tp-linker706wp-4g firmware
tp-linker707-m2
tp-linker707-m2 firmware
tp-linker7206
tp-linker7206 firmware
tp-linker7212pc
tp-linker7212pc firmware
tp-linker7406
tp-linker7406 firmware
tp-linker7412-m2
tp-linker7412-m2 firmware
tp-linker8411
tp-linker8411 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD