在 Omada 网关中已发现一个预身份验证的操作系统命令注入漏洞,该漏洞出现在配置为 OpenVPN 服务器运行的网关中,原因是 OpenVPN 连接建立过程中对用户提供的数据验证不足。未认证的远程攻击者可以在身份验证完成之前,通过提供精心构造的输入来影响后端的命令执行逻辑。 成功利用此漏洞可实现任意命令执行,可能导致受影响的设备被完全控制。 要利用该漏洞,需满足以下条件: 1. 已启用 OpenVPN 服务器功能; 2. 攻击者可以访问该 VPN 服务; 3. 攻击者能够发起 OpenVPN 连接尝试。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc | ER7406 v1 | < 1.3.4 Build 20260625 Rel.43136 |
affected |
| TP-Link Systems Inc | ER7412-M2 v1 | < 1.2.0 Build 20260630 Rel.82947 |
affected |
| TP-Link Systems Inc. | DR3150 v1 | < 1.0.1 Build 20260722 Rel.16854 |
affected |
| TP-Link Systems Inc. | DR3220v-4G v1 | < 1.2.0 Build 20260630 Rel.82652 |
affected |
| TP-Link Systems Inc. | DR3650v v1 | < 1.2.0 Build 20260630 Rel.83311 |
affected |
| TP-Link Systems Inc. | DR3650v-4G v1 | < 1.2.0 Build 20260630 Rel.83347 |
affected |
| TP-Link Systems Inc. | ER603WP-4G-Outdoor v1 | < 1.0.2 Build 20260723 Rel.43271 |
affected |
| TP-Link Systems Inc. | ER605 v2 | < 2.4.4 Build 20260630 Rel.14398 |
affected |
| TP-Link Systems Inc. | ER605W v2 | < 2.0.4 Build 20260723 Rel.43763 |
affected |
| TP-Link Systems Inc. | ER701-5G-Outdoor v1 | < 1.0.3 Build 20260723 Rel.40931 |
affected |
| TP-Link Systems Inc. | ER703WP-4G-Outdoor v1 | < 1.1.7 Build 20260723 Rel.41712 |
affected |
| TP-Link Systems Inc. | ER706W v1 | < 1.2.11 Build 20260723 Rel.41567 |
affected |
| TP-Link Systems Inc. | ER706W-4G v2 | < 2.1.11 Build 20260723 Rel.41624 |
affected |
| TP-Link Systems Inc. | ER706WP-4G v1 | < 1.1.11 Build 20260723 Rel.41624 |
affected |
| TP-Link Systems Inc. | ER707-M2 v1 | < 1.4.4 Build 20260625 Rel.43063 |
affected |
| TP-Link Systems Inc. | ER7206 v2 | < 2.3.5 Build 20260625 Rel.43136 |
affected |
| TP-Link Systems Inc. | ER7212PC v2 | < 2.4.3 Build 20260722 Rel.40250 |
affected |
| TP-Link Systems Inc. | ER8411 v1 | < 1.4.1 Build 20260708 Rel.64832 |
affected |
| TP-Link Systems Inc. | v1 | < 1.2.6 Build 20260723 Rel.41321 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | ER7212PC v2 | 0 ~ 2.4.3 Build 20260722 Rel.40250 | - |
|
| TP-Link Systems Inc. | ER605 v2 | 0 ~ 2.4.4 Build 20260630 Rel.14398 | - |
|
| TP-Link Systems Inc. | ER7206 v2 | 0 ~ 2.3.5 Build 20260625 Rel.43136 | - |
|
| TP-Link Systems Inc | ER7406 v1 | 0 ~ 1.3.4 Build 20260625 Rel.43136 | - |
|
| TP-Link Systems Inc. | ER707-M2 v1 | 0 ~ 1.4.4 Build 20260625 Rel.43063 | - |
|
| TP-Link Systems Inc | ER7412-M2 v1 | 0 ~ 1.2.0 Build 20260630 Rel.82947 | - |
|
| TP-Link Systems Inc. | ER8411 v1 | 0 ~ 1.4.1 Build 20260708 Rel.64832 | - |
|
| TP-Link Systems Inc. | ER706W v1 | 0 ~ 1.2.11 Build 20260723 Rel.41567 | - |
|
| TP-Link Systems Inc. | v1 | 0 ~ 1.2.6 Build 20260723 Rel.41321 | - |
|
| TP-Link Systems Inc. | ER706W-4G v2 | 0 ~ 2.1.11 Build 20260723 Rel.41624 | - |
|
| TP-Link Systems Inc. | ER706WP-4G v1 | 0 ~ 1.1.11 Build 20260723 Rel.41624 | - |
|
| TP-Link Systems Inc. | ER703WP-4G-Outdoor v1 | 0 ~ 1.1.7 Build 20260723 Rel.41712 | - |
|
| TP-Link Systems Inc. | DR3220v-4G v1 | 0 ~ 1.2.0 Build 20260630 Rel.82652 | - |
|
| TP-Link Systems Inc. | DR3650v v1 | 0 ~ 1.2.0 Build 20260630 Rel.83311 | - |
|
| TP-Link Systems Inc. | DR3650v-4G v1 | 0 ~ 1.2.0 Build 20260630 Rel.83347 | - |
|
| TP-Link Systems Inc. | ER603WP-4G-Outdoor v1 | 0 ~ 1.0.2 Build 20260723 Rel.43271 | - |
|
| TP-Link Systems Inc. | DR3150 v1 | 0 ~ 1.0.1 Build 20260722 Rel.16854 | - |
|
| TP-Link Systems Inc. | ER701-5G-Outdoor v1 | 0 ~ 1.0.3 Build 20260723 Rel.40931 | - |
|
| TP-Link Systems Inc. | ER605W v2 | 0 ~ 2.0.4 Build 20260723 Rel.43763 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19683 | 6.3 MEDIUM | Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada G |
| CVE-2026-9033 | 6.0 MEDIUM | Unauthenticated Captive Portal Session Termination and Forced Logout in Omada Gateways |
No comments yet