SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-1668

Under specific conditions, this flaw may result in unintended command execution.<br>An unauthenticated attacker with network access to the affected interface may cause memory corruption, service instability, or information disclosure.

HIGH 7.7EPSS 0.97%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when processing crafted requests. Under specific conditions, this flaw may result in unintended command execution.<br>An unauthenticated attacker with network access to the affected interface may cause memory corruption, service instability, or information disclosure. Successful exploitation may allow remote code execution or denial-of-service.

CVSS 4.0
7.7 HIGHCVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.97% probability · 60th percentile
CISA KEV
Not listed
Weakness
CWE-20, CWE-787
Affected
tp-link/omada sg2005p-pd firmware · tp-link/omada sg2008 firmware · tp-link/omada sg2008p firmware · tp-link/omada sg2016p firmware · tp-link/omada sg2210mp firmware · tp-link/omada sg2210p firmware · tp-link/omada sg2210xmp-m2 firmware · tp-link/omada sg2218 firmware · tp-link/omada sg2218p firmware · tp-link/omada sg2428lp firmware · tp-link/omada sg2428p firmware · tp-link/omada sg2452lp firmware · tp-link/omada sg3210 firmware · tp-link/omada sg3210xhp-m2 firmware · tp-link/omada sg3210x-m2 firmware · tp-link/omada sg3218xp-m2 firmware · tp-link/omada sg3428 firmware · tp-link/omada sg3428mp firmware · tp-link/omada sg3428x firmware · tp-link/omada sg3428xf firmware · +19 more
Source
f23511db-6c3e-4e32-a477-6aa17d310630

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.