目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-19586— Omada Gateway OpenVPN 服务器预认证 OS 命令注入漏洞

一分钟漏洞结论

影响对象
TP-Link Systems Inc. ER7212PC v2
利用判断
利用概率较高,应尽快评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Omada 网关中已发现一个预身份验证的操作系统命令注入漏洞,该漏洞出现在配置为 OpenVPN 服务器运行的网关中,原因是 OpenVPN 连接建立过程中对用户提供的数据验证不足。未认证的远程攻击者可以在身份验证完成之前,通过提供精心构造的输入来影响后端的命令执行逻辑。 成功利用此漏洞可实现任意命令执行,可能导致受影响的设备被完全控制。 要利用该漏洞,需满足以下条件: 1. 已启用 OpenVPN 服务器功能; 2. 攻击者可以访问该 VPN 服务; 3. 攻击者能够发起 OpenVPN 连接尝试。

CVSS 9.3 · Critical EPSS 5.04% · P92

影响版本矩阵 19

厂商产品 版本范围状态
TP-Link Systems Inc ER7406 v1 < 1.3.4 Build 20260625 Rel.43136 affected
TP-Link Systems Inc ER7412-M2 v1 < 1.2.0 Build 20260630 Rel.82947 affected
TP-Link Systems Inc. DR3150 v1 < 1.0.1 Build 20260722 Rel.16854 affected
TP-Link Systems Inc. DR3220v-4G v1 < 1.2.0 Build 20260630 Rel.82652 affected
TP-Link Systems Inc. DR3650v v1 < 1.2.0 Build 20260630 Rel.83311 affected
TP-Link Systems Inc. DR3650v-4G v1 < 1.2.0 Build 20260630 Rel.83347 affected
TP-Link Systems Inc. ER603WP-4G-Outdoor v1 < 1.0.2 Build 20260723 Rel.43271 affected
TP-Link Systems Inc. ER605 v2 < 2.4.4 Build 20260630 Rel.14398 affected
TP-Link Systems Inc. ER605W v2 < 2.0.4 Build 20260723 Rel.43763 affected
TP-Link Systems Inc. ER701-5G-Outdoor v1 < 1.0.3 Build 20260723 Rel.40931 affected
TP-Link Systems Inc. ER703WP-4G-Outdoor v1 < 1.1.7 Build 20260723 Rel.41712 affected
TP-Link Systems Inc. ER706W v1 < 1.2.11 Build 20260723 Rel.41567 affected
TP-Link Systems Inc. ER706W-4G v2 < 2.1.11 Build 20260723 Rel.41624 affected
TP-Link Systems Inc. ER706WP-4G v1 < 1.1.11 Build 20260723 Rel.41624 affected
TP-Link Systems Inc. ER707-M2 v1 < 1.4.4 Build 20260625 Rel.43063 affected
TP-Link Systems Inc. ER7206 v2 < 2.3.5 Build 20260625 Rel.43136 affected
TP-Link Systems Inc. ER7212PC v2 < 2.4.3 Build 20260722 Rel.40250 affected
TP-Link Systems Inc. ER8411 v1 < 1.4.1 Build 20260708 Rel.64832 affected
TP-Link Systems Inc. v1 < 1.2.6 Build 20260723 Rel.41321 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-19586 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways
来源: CVE Program / CVE List V5
Vulnerability Description
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.  Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
来源: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
TP-Link Systems Inc. ER7212PC v2 0 ~ 2.4.3 Build 20260722 Rel.40250 -
TP-Link Systems Inc. ER605 v2 0 ~ 2.4.4 Build 20260630 Rel.14398 -
TP-Link Systems Inc. ER7206 v2 0 ~ 2.3.5 Build 20260625 Rel.43136 -
TP-Link Systems Inc ER7406 v1 0 ~ 1.3.4 Build 20260625 Rel.43136 -
TP-Link Systems Inc. ER707-M2 v1 0 ~ 1.4.4 Build 20260625 Rel.43063 -
TP-Link Systems Inc ER7412-M2 v1 0 ~ 1.2.0 Build 20260630 Rel.82947 -
TP-Link Systems Inc. ER8411 v1 0 ~ 1.4.1 Build 20260708 Rel.64832 -
TP-Link Systems Inc. ER706W v1 0 ~ 1.2.11 Build 20260723 Rel.41567 -
TP-Link Systems Inc. v1 0 ~ 1.2.6 Build 20260723 Rel.41321 -
TP-Link Systems Inc. ER706W-4G v2 0 ~ 2.1.11 Build 20260723 Rel.41624 -
TP-Link Systems Inc. ER706WP-4G v1 0 ~ 1.1.11 Build 20260723 Rel.41624 -
TP-Link Systems Inc. ER703WP-4G-Outdoor v1 0 ~ 1.1.7 Build 20260723 Rel.41712 -
TP-Link Systems Inc. DR3220v-4G v1 0 ~ 1.2.0 Build 20260630 Rel.82652 -
TP-Link Systems Inc. DR3650v v1 0 ~ 1.2.0 Build 20260630 Rel.83311 -
TP-Link Systems Inc. DR3650v-4G v1 0 ~ 1.2.0 Build 20260630 Rel.83347 -
TP-Link Systems Inc. ER603WP-4G-Outdoor v1 0 ~ 1.0.2 Build 20260723 Rel.43271 -
TP-Link Systems Inc. DR3150 v1 0 ~ 1.0.1 Build 20260722 Rel.16854 -
TP-Link Systems Inc. ER701-5G-Outdoor v1 0 ~ 1.0.3 Build 20260723 Rel.40931 -
TP-Link Systems Inc. ER605W v2 0 ~ 2.0.4 Build 20260723 Rel.43763 -

二、漏洞 CVE-2026-19586 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-19586 的情报信息

登录查看更多情报信息。

CVE-2026-19586 厂商安全公告 (1)

CVE-2026-19586 厂商页面 (1)

同批安全公告 · TP-Link Systems Inc. · 2026-08-20 · 共 3 条

CVE-2026-19683 6.3 MEDIUM Omada Gateway DDNS认证凭据明文传输漏洞
CVE-2026-9033 6.0 MEDIUM Omada 网关未授权强制登出漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-19586

暂无评论


发表评论