PT-2026-79103 · Tp Link Systems+1 · Dr3150 V1+34
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Omada gateways (affected versions not specified)
Description
A pre-authentication OS command injection exists in Omada gateways configured as an OpenVPN Server. The issue stems from insufficient validation of client-supplied data during the OpenVPN connection establishment process. An unauthenticated remote attacker can provide specially crafted input to influence backend command execution logic, utilizing techniques such as awk injection. Successful exploitation requires the OpenVPN Server feature to be enabled and the VPN service to be reachable. This may allow arbitrary command execution, potentially leading to a full compromise of the device.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, disable the OpenVPN Server feature until a patch is available.
Exploit
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dr3150 V1
Dr3220V-4G V1
Dr3650V V1
Dr3650V-4G V1
Er603Wp-4G-Outdoor V1
Er605 V2
Er605W V2
Er701-5G-Outdoor V1
Er703Wp-4G-Outdoor V1
Er706W V1
Er706W-4G V2
Er706Wp-4G V1
Er707-M2 V1
Er7206 V2
Er7212Pc V2
Er7406 V1
Er7412-M2 V1
Er8411 V1
Dr3150 Firmware
Dr3220V-4G Firmware
Dr3650V-4G Firmware
Dr3650V Firmware
Er603Wp-4G-Outdoor Firmware
Er605 Firmware
Er701-5G-Outdoor Firmware
Er703Wp-4G-Outdoor Firmware
Er706W-4G Firmware
Er706W Firmware
Er707-M2 Firmware
Er7206 Firmware
Er7212Pc Firmware
Er7406 Firmware
Er7412-M2 Firmware
Er8411 Firmware
V1