Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-19586
TP-Link Systems Inc. ER7212PC v2 — Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 9.3 .0570 92.8 —
AFFECTED
Product Versions Fixed
ER7212PC v2 unspecified —
ER605 v2 unspecified —
ER7206 v2 unspecified —
ER7406 v1 unspecified —
ER707-M2 v1 unspecified —
ER7412-M2 v1 unspecified —
ER8411 v1 unspecified —
ER706W v1 unspecified —
v1 unspecified —
ER706W-4G v2 unspecified —
+ 9 more
TIMELINE
Aug 12 Reserved by TPLink
Aug 20 Published (CNA: TPLink)
Sep 3 EXPLOIT PUBLISHED — CVE-2026-19586 (TP-Link Systems Inc. ER7212PC v2). Public exploit reference added.
Description
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.
Successful exploitation may allow arbitrary command execution, potentially
leading to full compromise of the affected device.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 12, 2026 | Reserved | Reserved by TPLink |
| August 20, 2026 | Published | Published (CNA: TPLink) |
| September 3, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-19586 (TP-Link Systems Inc. ER7212PC v2). Public exploit reference added. |
Affected
Affected products and packages — 19 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| TP-Link Systems Inc. | ER7212PC v2 | — | — | — |
| TP-Link Systems Inc. | ER605 v2 | — | — | — |
| TP-Link Systems Inc. | ER7206 v2 | — | — | — |
| TP-Link Systems Inc | ER7406 v1 | — | — | — |
| TP-Link Systems Inc. | ER707-M2 v1 | — | — | — |
| TP-Link Systems Inc | ER7412-M2 v1 | — | — | — |
| TP-Link Systems Inc. | ER8411 v1 | — | — | — |
| TP-Link Systems Inc. | ER706W v1 | — | — | — |
| TP-Link Systems Inc. | v1 | — | — | — |
| TP-Link Systems Inc. | ER706W-4G v2 | — | — | — |
| TP-Link Systems Inc. | ER706WP-4G v1 | — | — | — |
| TP-Link Systems Inc. | ER703WP-4G-Outdoor v1 | — | — | — |
| TP-Link Systems Inc. | DR3220v-4G v1 | — | — | — |
| TP-Link Systems Inc. | DR3650v v1 | — | — | — |
| TP-Link Systems Inc. | DR3650v-4G v1 | — | — | — |
| TP-Link Systems Inc. | ER603WP-4G-Outdoor v1 | — | — | — |
| TP-Link Systems Inc. | DR3150 v1 | — | — | — |
| TP-Link Systems Inc. | ER701-5G-Outdoor v1 | — | — | — |
| TP-Link Systems Inc. | ER605W v2 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-19586 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.