Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19683— Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada Gateways

CVSS 6.3 · Medium EPSS 0.29% · P22

Affected Version Matrix 19

VendorProductVersion RangeStatus
TP-Link Systems IncER7406 v1< 1.3.4 Build 20260625 Rel.43136affected
TP-Link Systems IncER7412-M2 v1< 1.2.0 Build 20260630 Rel.82947affected
TP-Link Systems Inc.DR3150 v1< 1.0.1 Build 20260722 Rel.16854affected
TP-Link Systems Inc.DR3220v-4G v1< 1.2.0 Build 20260630 Rel.82652affected
TP-Link Systems Inc.DR3650v v1< 1.2.0 Build 20260630 Rel.83311affected
TP-Link Systems Inc.DR3650v-4G v1< 1.2.0 Build 20260630 Rel.83347affected
TP-Link Systems Inc.ER603WP-4G-Outdoor v1< 1.0.2 Build 20260723 Rel.43271affected
TP-Link Systems Inc.ER605 v2< 2.4.4 Build 20260630 Rel.14398affected
TP-Link Systems Inc.ER605W v2< 2.0.4 Build 20260723 Rel.43763affected
TP-Link Systems Inc.ER701-5G-Outdoor v1< 1.0.3 Build 20260723 Rel.40931affected
TP-Link Systems Inc.ER703WP-4G-Outdoor v1< 1.1.7 Build 20260723 Rel.41712affected
TP-Link Systems Inc.ER706W v1< 1.2.11 Build 20260723 Rel.41567affected
TP-Link Systems Inc.ER706W-4G v2< 2.1.11 Build 20260723 Rel.41624affected
TP-Link Systems Inc.ER706WP-4G v1< 1.1.11 Build 20260723 Rel.41624affected
TP-Link Systems Inc.ER707-M2 v1< 1.4.4 Build 20260625 Rel.43063affected
TP-Link Systems Inc.ER7206 v2< 2.3.5 Build 20260625 Rel.43136affected
TP-Link Systems Inc.ER7212PC v2< 2.4.3 Build 20260722 Rel.40250affected
TP-Link Systems Inc.ER8411 v1< 1.4.1 Build 20260708 Rel.64832affected
TP-Link Systems Inc.v1< 1.2.6 Build 20260723 Rel.41321affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-19683

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada Gateways
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path.  Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
敏感数据的明文传输
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
TP-Link Systems Inc.ER7212PC v2 0 ~ 2.4.3 Build 20260722 Rel.40250 -
TP-Link Systems Inc.ER605 v2 0 ~ 2.4.4 Build 20260630 Rel.14398 -
TP-Link Systems Inc.ER7206 v2 0 ~ 2.3.5 Build 20260625 Rel.43136 -
TP-Link Systems IncER7406 v1 0 ~ 1.3.4 Build 20260625 Rel.43136 -
TP-Link Systems Inc.ER707-M2 v1 0 ~ 1.4.4 Build 20260625 Rel.43063 -
TP-Link Systems IncER7412-M2 v1 0 ~ 1.2.0 Build 20260630 Rel.82947 -
TP-Link Systems Inc.ER8411 v1 0 ~ 1.4.1 Build 20260708 Rel.64832 -
TP-Link Systems Inc.ER706W v1 0 ~ 1.2.11 Build 20260723 Rel.41567 -
TP-Link Systems Inc.v1 0 ~ 1.2.6 Build 20260723 Rel.41321 -
TP-Link Systems Inc.ER706W-4G v2 0 ~ 2.1.11 Build 20260723 Rel.41624 -
TP-Link Systems Inc.ER706WP-4G v1 0 ~ 1.1.11 Build 20260723 Rel.41624 -
TP-Link Systems Inc.ER703WP-4G-Outdoor v1 0 ~ 1.1.7 Build 20260723 Rel.41712 -
TP-Link Systems Inc.DR3220v-4G v1 0 ~ 1.2.0 Build 20260630 Rel.82652 -
TP-Link Systems Inc.DR3650v v1 0 ~ 1.2.0 Build 20260630 Rel.83311 -
TP-Link Systems Inc.DR3650v-4G v1 0 ~ 1.2.0 Build 20260630 Rel.83347 -
TP-Link Systems Inc.ER603WP-4G-Outdoor v1 0 ~ 1.0.2 Build 20260723 Rel.43271 -
TP-Link Systems Inc.DR3150 v1 0 ~ 1.0.1 Build 20260722 Rel.16854 -
TP-Link Systems Inc.ER701-5G-Outdoor v1 0 ~ 1.0.3 Build 20260723 Rel.40931 -
TP-Link Systems Inc.ER605W v2 0 ~ 2.0.4 Build 20260723 Rel.43763 -

II. Public POCs for CVE-2026-19683

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19683

登录查看更多情报信息。

Vendor Advisories for CVE-2026-19683 (1)

Vendor Pages for CVE-2026-19683 (1)

Same Patch Batch · TP-Link Systems Inc. · 2026-08-20 · 3 CVEs total

CVE-2026-195869.3 CRITICALPre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gatew
CVE-2026-90336.0 MEDIUMUnauthenticated Captive Portal Session Termination and Forced Logout in Omada Gateways

IV. Related Vulnerabilities

V. Comments for CVE-2026-19683

No comments yet


Leave a comment