CVE-2026-19586General(tp-link / dr3150)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch tp-link dr3150 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.  Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.

2.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dr3150
  • dr3150_firmware
  • dr3220v-4g
  • dr3220v-4g_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-08-21); latest day: 2
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
dr3150dr3150_firmwaredr3220v-4gdr3220v-4g_firmwaredr3650vdr3650v-4gdr3650v-4g_firmwaredr3650v_firmwareer603wp-4g-outdoorer603wp-4g-outdoor_firmware

2 versions affected across 36 products

Deep dive

Activity timeline8 mentions / 3d
01223Mentions · 2026-08-21: 3Mentions · 2026-08-30: 3Mentions · 2026-09-11: 2PoC Mentioned / Linked · 2026-08-30: 1Patch / Workaround · 2026-08-21: 2Patch / Workaround · 2026-09-11: 1Technical Details · 2026-08-21: 2Technical Details · 2026-08-30: 1Technical Details · 2026-09-11: 108-2108-3009-11
Signal classification3 categories
General
337.5%
Disclosure
337.5%
Patch
225.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-08-213
General1Patch2
2026-08-303
Disclosure1General2
2026-09-112
Disclosure2
Full discourse8 posts
  • kokumօtօ@__kokumoto
    Patch

    TP-Link Omadaに重大(Critical)な脆弱性。CVE-2026-19586はCVSSスコア9.3で無認証OSコマンドインジェクション。ゲートウェイがOpenVPNサーバを起動している場合に影響。実際の悪用やPoC(攻撃の概念実証コード)は未確認。その他脆弱性2件と併せ修正。 https://securityonline.info/cve-2026-19586-omada-command-injection/

    Post summary

    A critical unauthenticated OS command injection (CVE‑2026‑19586) in TP‑Link Omada with CVSS 9.3 is reported; a patch is noted and no PoC or active exploitation is confirmed.

    100411.0K
    7.8K followersView on X
  • Matt Graham@mattgsys
    Disclosure

    @__kokumoto Here is my writeup on how I found the issue: https://mattg.systems/posts/cve-2026-19586/

    Post summary

    The tweet links to a writeup detailing a newly discovered vulnerability, but offers no exploit code, patch information, or evidence of active exploitation.

    1001080
    1 followersView on X
  • Matt Graham@mattgsys
    General

    New blog post: TP-Link Omada SSL VPN Unauthenticated RCE (CVE-2026-19586) (CRITICAL) https://mattg.systems/posts/cve-2026-19586/ A command injection vulnerability within the SSL VPN authentication handling of multiple TP-Link gateways/routers. Some interesting awk injection techniques here.

    Post summary

    The article announces a critical command injection flaw in TP‑Link Omada SSL VPN routers, without evidence of an exploit, PoC, or patch, and no active exploitation reports.

    0000195
    1 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Disclosure

    19機種ぶんの修正版を目で突き合わせると必ず間違えるので、判定スクリプトに落としました。バージョン比較を文字列でやると 2.4.10 が 2.4.4 より古いと判定されます。安全側ではなく危険を見落とす向きに倒れないかを実測で確かめています。 https://blog.hashito.biz/2026/09/11/omada-cve-2026-19586-openvpn-preauth-command-injection/

    Post summary

    The post links to a blog article announcing CVE‑2026‑19586, an OpenVPN pre‑authentication command injection vulnerability, but it provides no PoC, exploit code, patch, or detailed technical specifics.

    0000056
    556 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Disclosure

    TP-Link Omada ゲートウェイに認証前のOSコマンドインジェクション。NVD評価はCVSS 9.8。成立するのはOpenVPNサーバ機能を有効にしている場合だけですが、対象は19機種で修正版の下限が機種ごとに違います。型番だけでなくHWバージョンも確認してください。 https://cve.autoarticles.net/cve/CVE-2026-19586

    Post summary

    TP‑Link Omada gateways are vulnerable to a pre‑authentication OS command injection (CVE‑2026‑19586) with a CVSS score 9.8, affecting 19 models when OpenVPN is enabled; vendor patches are available and users should verify model and HW version.

    0000061
    556 followersView on X
  • Matt Graham@mattgsys
    General

    @Insylux Here is my writeup on how I found the issue: https://mattg.systems/posts/cve-2026-19586/

    Post summary

    The post merely references a writeup about CVE‑2026‑19586 without providing any specific technical details, PoC, or evidence of exploitation.

    0000086
    1 followersView on X
  • SecureShield@SecureShield_
    General

    一次情報(NVD): https://nvd.nist.gov/vuln/detail/CVE-2026-19586 参照元(ベンダー等): https://www.omadanetworks.com/en/support/download/, https://www.omadanetworks.com/us/support/download/

    Post summary

    The post merely links to the NVD entry for CVE‑2026‑19586 and references vendor download pages, without providing additional technical or exploit information.

    0000031
    26 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    CVE-2026-19586 (CVSS 9.3) is a pre-authentication OS command injection in TP-Link Omada gateways running OpenVPN Server. Patch the firmware now. #Omada #TPLink #CVE202619586 #CommandInjection #OpenVPN #NetworkSecurity https://securityonline.info/cve-2026-19586-omada-command-injection/

    Post summary

    The post announces a high‑severity OS command injection vulnerability (CVE‑2026‑19586) in TP‑Link Omada gateways, urging immediate firmware patching.

    00000396
    12.9K followersView on X
CPE platform detail37 entries

37 of 37 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linkdr3150---
OStp-linkdr3150_firmware---
HWtp-linkdr3220v-4g---
OStp-linkdr3220v-4g_firmware---
HWtp-linkdr3650v---
HWtp-linkdr3650v-4g---
OStp-linkdr3650v-4g_firmware---
OStp-linkdr3650v_firmware---
HWtp-linker603wp-4g-outdoor---
OStp-linker603wp-4g-outdoor_firmware---
HWtp-linker6052.0--
OStp-linker605_firmware---
HWtp-linker605w2.0--
OStp-linker605w_firmware---
HWtp-linker701-5g-outdoor---
OStp-linker701-5g-outdoor_firmware---
HWtp-linker703wp-4g-outdoor---
OStp-linker703wp-4g-outdoor_firmware---
HWtp-linker706w---
HWtp-linker706w-4g---
HWtp-linker706w-4g2.0--
OStp-linker706w-4g_firmware---
OStp-linker706w_firmware---
HWtp-linker706wp-4g---
OStp-linker706wp-4g_firmware---
HWtp-linker707-m2---
OStp-linker707-m2_firmware---
HWtp-linker72062.0--
OStp-linker7206_firmware---
HWtp-linker7212pc2.0--
OStp-linker7212pc_firmware---
HWtp-linker7406---
OStp-linker7406_firmware---
HWtp-linker7412-m2---
OStp-linker7412-m2_firmware---
HWtp-linker8411---
OStp-linker8411_firmware---

Explore more