ReviewCritical

CVE-2026-19586

TP-Link Systems Inc. ER7212PC v2, ER605 v2, ER7206 v2

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt. Successful exploitation may allow arbitrary com...

CVSS
9.3
EPSS
5.09%
91.8% percentile
CISA KEV
Not listed
Published
2026.08.21
PRIORITY ASSESSMENT

Review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability5.09%
Technical severityCVSS 9.3

Vulnerability overview

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt. Successful exploitation may allow arbitrary com...

Affected product and versions

Product
TP-Link Systems Inc. ER7212PC v2, ER605 v2, ER7206 v2
Affected versions
< 2.4.3 Build 20260722 Rel.40250, < 2.4.4 Build 20260630 Rel.14398, < 2.3.5 Build 20260625 Rel.43136, < 1.3.4 Build 20260625 Rel.43136, < 1.4.4 Build 20260625 Rel.43063, < 1.2.0 Build 20260630 Rel.82947, < 1.4.1 Build 20260708 Rel.64832, < 1.2.11 Build 20260723 Rel.41567, < 1.2.6 Build 20260723 Rel.41321, < 2.1.11 Build 20260723 Rel.41624, < 1.1.11 Build 20260723 Rel.41624, < 1.1.7 Build 20260723 Rel.41712, < 1.2.0 Build 20260630 Rel.82652, < 1.2.0 Build 20260630 Rel.83311, < 1.2.0 Build 20260630 Rel.83347, < 1.0.2 Build 20260723 Rel.43271, < 1.0.1 Build 20260722 Rel.16854, < 1.0.3 Build 20260723 Rel.40931, < 2.0.4 Build 20260723 Rel.43763
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that TP-Link Systems Inc. ER7212PC v2, ER605 v2, ER7206 v2 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-78