boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-19586

TP-Link Systems Inc. ER7212PC v2 — Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0570   92.8     —
AFFECTED
  Product       Versions     Fixed
  ER7212PC v2   unspecified  —
  ER605 v2      unspecified  —
  ER7206 v2     unspecified  —
  ER7406 v1     unspecified  —
  ER707-M2 v1   unspecified  —
  ER7412-M2 v1  unspecified  —
  ER8411 v1     unspecified  —
  ER706W v1     unspecified  —
  v1            unspecified  —
  ER706W-4G v2  unspecified  —
  + 9 more
TIMELINE
  Aug 12  Reserved by TPLink
  Aug 20  Published (CNA: TPLink)
  Sep 3   EXPLOIT PUBLISHED — CVE-2026-19586 (TP-Link Systems Inc. ER7212PC v2). Public exploit reference added.
CWE-78 · CNA: TPLink · CVSS v4.0 · 4 references · NVD status: Analyzed

Description

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.  Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 12, 2026ReservedReserved by TPLink
August 20, 2026PublishedPublished (CNA: TPLink)
September 3, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-19586 (TP-Link Systems Inc. ER7212PC v2). Public exploit reference added.

Affected

Affected products and packages — 19 rows
VendorProduct / PackageEcosystemVersion introducedFixed
TP-Link Systems Inc.ER7212PC v2———
TP-Link Systems Inc.ER605 v2———
TP-Link Systems Inc.ER7206 v2———
TP-Link Systems IncER7406 v1———
TP-Link Systems Inc.ER707-M2 v1———
TP-Link Systems IncER7412-M2 v1———
TP-Link Systems Inc.ER8411 v1———
TP-Link Systems Inc.ER706W v1———
TP-Link Systems Inc.v1———
TP-Link Systems Inc.ER706W-4G v2———
TP-Link Systems Inc.ER706WP-4G v1———
TP-Link Systems Inc.ER703WP-4G-Outdoor v1———
TP-Link Systems Inc.DR3220v-4G v1———
TP-Link Systems Inc.DR3650v v1———
TP-Link Systems Inc.DR3650v-4G v1———
TP-Link Systems Inc.ER603WP-4G-Outdoor v1———
TP-Link Systems Inc.DR3150 v1———
TP-Link Systems Inc.ER701-5G-Outdoor v1———
TP-Link Systems Inc.ER605W v2———

Weaknesses

CWE-78

References (4)

Related

Authoritative record: CVE-2026-19586 at cve.org

Vendors: tp-link systems

Weaknesses: CWE-78

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-19586 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.