CVE-2025-7851 — CVSS 9.8 (critical): An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
CVE-2026-19586 — CVSS 9.8 (critical): A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server…
CVE-2025-6541 — CVSS 8.8 (high): An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
CVE-2026-19683 — CVSS 7.4 (high): A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS…
CVE-2025-7850 — CVSS 7.2 (high): A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
CVE-2025-9290 — CVSS 5.9 (medium): An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper…
CVE-2026-9033 — CVSS 4.3 (medium): An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal…