SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-19586

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment.

CRITICAL 9.3EPSS 5.70%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (5.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.  Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.

CVSS 4.0
9.3 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
5.70% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
tp-link/er7212pc firmware · tp-link/er605 firmware · tp-link/er605w firmware · tp-link/er7206 firmware · tp-link/er7406 firmware · tp-link/er707-m2 firmware · tp-link/er7412-m2 firmware · tp-link/er8411 firmware · tp-link/er706w firmware · tp-link/er706w-4g firmware · tp-link/er706wp-4g firmware · tp-link/er703wp-4g-outdoor firmware · tp-link/er603wp-4g-outdoor firmware · tp-link/er701-5g-outdoor firmware · tp-link/dr3220v-4g firmware · tp-link/dr3650v firmware · tp-link/dr3650v-4g firmware · tp-link/dr3150 firmware
Source
f23511db-6c3e-4e32-a477-6aa17d310630

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.