PT-2026-79104 · Tp Link Systems+1 · Dr3150 V1+34
CVE-2026-19683
·
Published
2026-08-20
·
Updated
2026-08-20
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path.
Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dr3150 V1
Dr3220V-4G V1
Dr3650V V1
Dr3650V-4G V1
Er603Wp-4G-Outdoor V1
Er605 V2
Er605W V2
Er701-5G-Outdoor V1
Er703Wp-4G-Outdoor V1
Er706W V1
Er706W-4G V2
Er706Wp-4G V1
Er707-M2 V1
Er7206 V2
Er7212Pc V2
Er7406 V1
Er7412-M2 V1
Er8411 V1
Dr3150 Firmware
Dr3220V-4G Firmware
Dr3650V-4G Firmware
Dr3650V Firmware
Er603Wp-4G-Outdoor Firmware
Er605 Firmware
Er701-5G-Outdoor Firmware
Er703Wp-4G-Outdoor Firmware
Er706W-4G Firmware
Er706W Firmware
Er707-M2 Firmware
Er7206 Firmware
Er7212Pc Firmware
Er7406 Firmware
Er7412-M2 Firmware
Er8411 Firmware
V1