ctipilot.ch

TP-Link / Omada Networks PSIRT

tp-link-omada-psirt · A · candidate

https://support.omadanetworks.com/us/security-advisory/

vulnsvendor-psirtlang: enfetch failures: 0quiet periods: 0last fetch: 2026-08-22

Added 2026-08-22 as this run's single new candidate, to close a discovery gap the run hit directly: TP-Link's Omada gateway line is a common SMB / branch-office / public-sector edge device across Europe, and its August 2026 advisory (pre-authentication OS command injection in the OpenVPN server, CVE-2026-19586) reached this pipeline only through BSI CERT-Bund with the vendor's own per-model firmware table unread — the first surfacing pass concluded the vendor advisory was unreachable and composed from NVD instead. FETCH (verified 2026-08-22): the advisory LANDING and SEARCH pages at omadanetworks.com are a JavaScript-only application that returns no content to any transport, but the PER-ADVISORY document path IS server-rendered and reads cleanly through `python3 tools/fetch_source.py url https://support.omadanetworks.com/us/document/<id>/` — e.g. document 132084 for the August 2026 multi-CVE advisory, which carries per-CVE CVSS 4.0 vectors, root-cause text, exploitation preconditions, the vendor's own workaround, and a 19-row per-model/per-hardware-version fixed-firmware table that the CVE records do not reproduce. REUSABLE RECIPE, worth generalising beyond this vendor: the reliable way to obtain the document id is the referencing national-CERT CSAF record's external-reference field — BSI CERT-Bund's WID-SEC JSON carried it directly (`fetch_source.py bsi-csaf WID-SEC-2026-2964`) — rather than trying to crawl the vendor's own single-page application. Candidate: promote to active after 3 contributing runs.

Cited in 1 entry

Citation cadence

Citation days per ISO week (1 weeks of coverage span, total 1).