目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-19683— Omada Gateway DDNS认证凭据明文传输漏洞

CVSS 6.3 · Medium

Affected Version Matrix 19

ベンダープロダクトVersion Rangeステータス
TP-Link Systems IncER7406 v1< 1.3.4 Build 20260625 Rel.43136affected
TP-Link Systems IncER7412-M2 v1< 1.2.0 Build 20260630 Rel.82947affected
TP-Link Systems Inc.DR3150 v1< 1.0.1 Build 20260722 Rel.16854affected
TP-Link Systems Inc.DR3220v-4G v1< 1.2.0 Build 20260630 Rel.82652affected
TP-Link Systems Inc.DR3650v v1< 1.2.0 Build 20260630 Rel.83311affected
TP-Link Systems Inc.DR3650v-4G v1< 1.2.0 Build 20260630 Rel.83347affected
TP-Link Systems Inc.ER603WP-4G-Outdoor v1< 1.0.2 Build 20260723 Rel.43271affected
TP-Link Systems Inc.ER605 v2< 2.4.4 Build 20260630 Rel.14398affected
TP-Link Systems Inc.ER605W v2< 2.0.4 Build 20260723 Rel.43763affected
TP-Link Systems Inc.ER701-5G-Outdoor v1< 1.0.3 Build 20260723 Rel.40931affected
TP-Link Systems Inc.ER703WP-4G-Outdoor v1< 1.1.7 Build 20260723 Rel.41712affected
TP-Link Systems Inc.ER706W v1< 1.2.11 Build 20260723 Rel.41567affected
TP-Link Systems Inc.ER706W-4G v2< 2.1.11 Build 20260723 Rel.41624affected
TP-Link Systems Inc.ER706WP-4G v1< 1.1.11 Build 20260723 Rel.41624affected
TP-Link Systems Inc.ER707-M2 v1< 1.4.4 Build 20260625 Rel.43063affected
TP-Link Systems Inc.ER7206 v2< 2.3.5 Build 20260625 Rel.43136affected
TP-Link Systems Inc.ER7212PC v2< 2.4.3 Build 20260722 Rel.40250affected
TP-Link Systems Inc.ER8411 v1< 1.4.1 Build 20260708 Rel.64832affected
TP-Link Systems Inc.v1< 1.2.6 Build 20260723 Rel.41321affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-19683の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada Gateways
ソース: CVE Program / CVE List V5
脆弱性説明
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path.  Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
敏感数据的明文传输
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
TP-Link Systems Inc.ER7212PC v2 0 ~ 2.4.3 Build 20260722 Rel.40250 -
TP-Link Systems Inc.ER605 v2 0 ~ 2.4.4 Build 20260630 Rel.14398 -
TP-Link Systems Inc.ER7206 v2 0 ~ 2.3.5 Build 20260625 Rel.43136 -
TP-Link Systems IncER7406 v1 0 ~ 1.3.4 Build 20260625 Rel.43136 -
TP-Link Systems Inc.ER707-M2 v1 0 ~ 1.4.4 Build 20260625 Rel.43063 -
TP-Link Systems IncER7412-M2 v1 0 ~ 1.2.0 Build 20260630 Rel.82947 -
TP-Link Systems Inc.ER8411 v1 0 ~ 1.4.1 Build 20260708 Rel.64832 -
TP-Link Systems Inc.ER706W v1 0 ~ 1.2.11 Build 20260723 Rel.41567 -
TP-Link Systems Inc.v1 0 ~ 1.2.6 Build 20260723 Rel.41321 -
TP-Link Systems Inc.ER706W-4G v2 0 ~ 2.1.11 Build 20260723 Rel.41624 -
TP-Link Systems Inc.ER706WP-4G v1 0 ~ 1.1.11 Build 20260723 Rel.41624 -
TP-Link Systems Inc.ER703WP-4G-Outdoor v1 0 ~ 1.1.7 Build 20260723 Rel.41712 -
TP-Link Systems Inc.DR3220v-4G v1 0 ~ 1.2.0 Build 20260630 Rel.82652 -
TP-Link Systems Inc.DR3650v v1 0 ~ 1.2.0 Build 20260630 Rel.83311 -
TP-Link Systems Inc.DR3650v-4G v1 0 ~ 1.2.0 Build 20260630 Rel.83347 -
TP-Link Systems Inc.ER603WP-4G-Outdoor v1 0 ~ 1.0.2 Build 20260723 Rel.43271 -
TP-Link Systems Inc.DR3150 v1 0 ~ 1.0.1 Build 20260722 Rel.16854 -
TP-Link Systems Inc.ER701-5G-Outdoor v1 0 ~ 1.0.3 Build 20260723 Rel.40931 -
TP-Link Systems Inc.ER605W v2 0 ~ 2.0.4 Build 20260723 Rel.43763 -

II. CVE-2026-19683の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-19683のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-19683 厂商安全公告 (1)

CVE-2026-19683 厂商页面 (1)

Same Patch Batch · TP-Link Systems Inc. · 2026-08-20 · 3 CVEs total

CVE-2026-195869.3 CRITICALPre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gatew
CVE-2026-90336.0 MEDIUMUnauthenticated Captive Portal Session Termination and Forced Logout in Omada Gateways

IV. 関連脆弱性

V. CVE-2026-19683へのコメント

まだコメントはありません


コメントを残す