CVE-2026-19586

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.  Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:er7212pc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er7212pc:2.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tp-link:er605_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er605:2.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tp-link:er605w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er605w:2.0:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:tp-link:er7206_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er7206:2.0:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:tp-link:er7406_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er7406:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:tp-link:er707-m2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er707-m2:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:tp-link:er7412-m2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er7412-m2:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:tp-link:er8411_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er8411:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:tp-link:er706w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er706w:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:tp-link:er706w-4g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er706w-4g:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:tp-link:er706w-4g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er706w-4g:2.0:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:tp-link:er706wp-4g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er706wp-4g:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:tp-link:er703wp-4g-outdoor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er703wp-4g-outdoor:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:tp-link:er603wp-4g-outdoor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er603wp-4g-outdoor:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:tp-link:er701-5g-outdoor_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:er701-5g-outdoor:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:tp-link:dr3220v-4g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:dr3220v-4g:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:tp-link:dr3650v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:dr3650v:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:tp-link:dr3650v-4g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:dr3650v-4g:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:tp-link:dr3150_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:dr3150:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-20 19:16

Updated : 2026-09-03 15:05


NVD link : CVE-2026-19586

Mitre link : CVE-2026-19586

CVE.ORG link : CVE-2026-19586


JSON object : View

Products Affected

tp-link

  • er7206
  • er8411
  • er7206_firmware
  • dr3220v-4g
  • er706wp-4g_firmware
  • dr3650v
  • er7412-m2
  • er7212pc
  • er605w
  • er605_firmware
  • dr3650v-4g
  • er706w-4g_firmware
  • er703wp-4g-outdoor
  • er701-5g-outdoor_firmware
  • dr3650v_firmware
  • er706w
  • dr3150_firmware
  • er605w_firmware
  • er605
  • er706wp-4g
  • dr3650v-4g_firmware
  • er603wp-4g-outdoor
  • er7406
  • er706w-4g
  • er7406_firmware
  • er707-m2
  • er706w_firmware
  • er707-m2_firmware
  • er7412-m2_firmware
  • er603wp-4g-outdoor_firmware
  • er8411_firmware
  • dr3220v-4g_firmware
  • dr3150
  • er701-5g-outdoor
  • er703wp-4g-outdoor_firmware
  • er7212pc_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')