CVE-2026-19586 Details
Description
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt. Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://mattg.systems/posts/cve-2026-19586/ | TPLink | ExploitThird Party Advisory |
| https://www.omadanetworks.com/en/support/download/ | TPLink | Product |
| https://www.omadanetworks.com/us/support/download/ | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5256/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link er7212pc firmware | < 2.4.3 |
CPE
Remediation
| |
| tp-link er7212pc | 2.0 |
CPE
Remediation
| |
| tp-link er605 firmware | < 2.4.4 |
CPE
Remediation
| |
| tp-link er605 | 2.0 |
CPE
Remediation
| |
| tp-link er605w firmware | < 2.0.4 |
CPE
Remediation
| |
| tp-link er605w | 2.0 |
CPE
Remediation
| |
| tp-link er7206 firmware | < 2.3.5 |
CPE
Remediation
| |
| tp-link er7206 | 2.0 |
CPE
Remediation
| |
| tp-link er7406 firmware | < 1.3.4 |
CPE
Remediation
| |
| tp-link er7406 | All versions |
CPE
Remediation
| |
| tp-link er707-m2 firmware | < 1.4.4 |
CPE
Remediation
| |
| tp-link er707-m2 | All versions |
CPE
Remediation
| |
| tp-link er7412-m2 firmware | < 1.2.0 |
CPE
Remediation
| |
| tp-link er7412-m2 | All versions |
CPE
Remediation
| |
| tp-link er8411 firmware | < 1.4.1 |
CPE
Remediation
| |
| tp-link er8411 | All versions |
CPE
Remediation
| |
| tp-link er706w firmware | < 1.2.11 |
CPE
Remediation
| |
| tp-link er706w | All versions |
CPE
Remediation
| |
| tp-link er706w-4g firmware | < 1.2.6 < 2.1.11 |
CPE
Remediation
| |
| tp-link er706w-4g | 2.0 |
CPE
Remediation
| |
| tp-link er706wp-4g firmware | < 1.1.11 |
CPE
Remediation
| |
| tp-link er706wp-4g | All versions |
CPE
Remediation
| |
| tp-link er703wp-4g-outdoor firmware | < 1.1.7 |
CPE
Remediation
| |
| tp-link er703wp-4g-outdoor | All versions |
CPE
Remediation
| |
| tp-link er603wp-4g-outdoor firmware | < 1.0.2 |
CPE
Remediation
| |
| tp-link er603wp-4g-outdoor | All versions |
CPE
Remediation
| |
| tp-link er701-5g-outdoor firmware | < 1.0.3 |
CPE
Remediation
| |
| tp-link er701-5g-outdoor | All versions |
CPE
Remediation
| |
| tp-link dr3220v-4g firmware | < 1.2.0 |
CPE
Remediation
| |
| tp-link dr3220v-4g | All versions |
CPE
Remediation
| |
| tp-link dr3650v firmware | < 1.2.0 |
CPE
Remediation
| |
| tp-link dr3650v | All versions |
CPE
Remediation
| |
| tp-link dr3650v-4g firmware | < 1.2.0 |
CPE
Remediation
| |
| tp-link dr3650v-4g | All versions |
CPE
Remediation
| |
| tp-link dr3150 firmware | < 1.0.1 |
CPE
Remediation
| |
| tp-link dr3150 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | Initial Analysis | [email protected] |
| Aug 28, 2026 | CVE Modified | TPLink |
| Aug 21, 2026 | CVE Modified | CISA-ADP |
| Aug 20, 2026 | New CVE Received | TPLink |
| Aug 20, 2026 | CVE Modified | CISA-ADP |