CVE-2026-1668
Under specific conditions, this flaw may result in unintended command execution.<br>An unauthenticated attacker with network access to the affected interface may cause memory corruption, service instability, or information disclosure.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when processing crafted requests. Under specific conditions, this flaw may result in unintended command execution.<br>An unauthenticated attacker with network access to the affected interface may cause memory corruption, service instability, or information disclosure. Successful exploitation may allow remote code execution or denial-of-service.
- CVSS 4.0
- 7.7 HIGHCVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-787
- Affected
- tp-link/omada sg2005p-pd firmware · tp-link/omada sg2008 firmware · tp-link/omada sg2008p firmware · tp-link/omada sg2016p firmware · tp-link/omada sg2210mp firmware · tp-link/omada sg2210p firmware · tp-link/omada sg2210xmp-m2 firmware · tp-link/omada sg2218 firmware · tp-link/omada sg2218p firmware · tp-link/omada sg2428lp firmware · tp-link/omada sg2428p firmware · tp-link/omada sg2452lp firmware · tp-link/omada sg3210 firmware · tp-link/omada sg3210xhp-m2 firmware · tp-link/omada sg3210x-m2 firmware · tp-link/omada sg3218xp-m2 firmware · tp-link/omada sg3428 firmware · tp-link/omada sg3428mp firmware · tp-link/omada sg3428x firmware · tp-link/omada sg3428xf firmware · +19 more
- Source
- f23511db-6c3e-4e32-a477-6aa17d310630
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.