Tp Link Systems · Dr3150 V1 · CVE-2026-19586
**Name of the Vulnerable Software and Affected Versions**
Omada gateways (affected versions not specified)
**Description**
A pre-authentication OS command injection exists in Omada gateways configured as an OpenVPN Server. The issue stems from insufficient validation of client-supplied data during the OpenVPN connection establishment process. An unauthenticated remote attacker can provide specially crafted input to influence backend command execution logic, utilizing techniques such as awk injection. Successful exploitation requires the OpenVPN Server feature to be enabled and the VPN service to be reachable. This may allow arbitrary command execution, potentially leading to a full compromise of the device.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, disable the OpenVPN Server feature until a patch is available.