2026-08-22HIGHThe fixed-firmware table runs to nineteen rows, and two units sharing a model name need different builds
TP-Link Omada gateways, pre-authentication OS command injection in the OpenVPN server; fixed per hardware revision in the vendor firmware table
cve · CVE-2026-19586
Coverage
1
first 2026-08-22 → last 2026-08-22
Latest activity
2026-08-22
The fixed-firmware table runs to nineteen rows, and two units sharing a model name need different builds
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, telco
Sources cited
2
2 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-19586, newest first. Check the date before acting on an older one.
- Inventory Omada gateways against TP-Link's per-model, per-hardware-version remediation table and upgrade any unit below its own row; the table is keyed on hardware revision, not model name, so ER706W-4G v1 needs 1.2.6 Build 20260723 Rel.41321 while v2 needs 2.1.11 Build 20260723 Rel.41624. Where a unit cannot be upgraded this week and OpenVPN Server is enabled, apply the vendor's stated workaround: disable that feature, or restrict the OpenVPN service to trusted source addresses so it is not answering the public internet.2026-08-22CVE-2026-19586 +2
Defender insights
What each entry about CVE-2026-19586 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
TP-Link Omada Gateway DR3150TP-Link Omada Gateway DR3220v-4GTP-Link Omada Gateway DR3650vTP-Link Omada Gateway DR3650v-4GTP-Link Omada Gateway ER603WP-4G-OutdoorTP-Link Omada Gateway ER605TP-Link Omada Gateway ER605WTP-Link Omada Gateway ER701-5G-OutdoorTP-Link Omada Gateway ER703WP-4G-OutdoorTP-Link Omada Gateway ER706WTP-Link Omada Gateway ER706W-4GTP-Link Omada Gateway ER706WP-4GTP-Link Omada Gateway ER707-M2TP-Link Omada Gateway ER7206TP-Link Omada Gateway ER7212PCTP-Link Omada Gateway ER7406
ATT&CK techniques (3 across 4 tactics)
3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- Credential AccessNetwork Sniffing
- DiscoveryNetwork Sniffing
- ImpactEndpoint Denial of Service
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-22/cve-2026-19586-tp-link-omada-openvpn-preauth-injection · ATT&CK page ↗
Credential Access TA0006
T1040Network Sniffing×1
Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.
Evidence: 2026-08-22/cve-2026-19586-tp-link-omada-openvpn-preauth-injection · ATT&CK page ↗
Discovery TA0007
T1040Network Sniffing×1
Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.
Evidence: 2026-08-22/cve-2026-19586-tp-link-omada-openvpn-preauth-injection · ATT&CK page ↗
Impact TA0040
T1499Endpoint Denial of Service×1
Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users. Endpoint DoS can be performed by exhausting the system resources those services are hosted on or exploiting the system to cause a persistent crash condition. Example services include websites, email services, DNS, and web-based applications. Adversaries have been observed conducting DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.
Evidence: 2026-08-22/cve-2026-19586-tp-link-omada-openvpn-preauth-injection · ATT&CK page ↗
Entries about TP-Link Omada gateways, pre-authentication OS command injection in the OpenVPN server; fixed per hardware revision in the vendor firmware table (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- TP-Link Omada Gateway DR3150×1
- TP-Link Omada Gateway DR3220v-4G×1
- TP-Link Omada Gateway DR3650v×1
- TP-Link Omada Gateway DR3650v-4G×1
- TP-Link Omada Gateway ER603WP-4G-Outdoor×1
- TP-Link Omada Gateway ER605×1
- TP-Link Omada Gateway ER605W×1
- TP-Link Omada Gateway ER701-5G-Outdoor×1
Where this entity is cited
Source distribution
- support.omadanetworks.com1 (50%)
- wid.cert-bund.de1 (50%)