VYPR

Omada gateways

by Omada Networks

CVEs (4)

  • CVE-2026-19586CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.06

    A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide…

  • CVE-2025-7851CriOct 21, 2025
    risk 0.64cvss 9.8epss 0.01

    An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.

  • CVE-2026-19683HigAug 20, 2026
    risk 0.48cvss 7.4epss 0.00

    A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an…

  • CVE-2025-7850HigOct 21, 2025
    risk 0.47cvss 7.2epss 0.03

    A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.