« Back to list

Tp-link

Tp-link Er605 Firmware: vulnerabilities and CVEs

Tp-link Er605 Firmware has 8 published vulnerabilities, 8 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs8
Last 12 months8
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-9033Medium (6)0.28%—Aug 20, 2026
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active…
CVE-2026-19683Medium (6.3)0.25%—Aug 20, 2026
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An…
CVE-2026-19586Critical (9.3)5.7%—Aug 20, 2026
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection…
CVE-2025-9290Medium (6)0.22%—Jan 23, 2026
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and…
CVE-2025-7851High (8.7)0.67%—Oct 21, 2025
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
CVE-2025-7850Critical (9.3)3.3%—Oct 21, 2025
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
CVE-2025-6542Critical (9.3)1.0%—Oct 21, 2025
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
CVE-2025-6541High (8.6)0.69%—Oct 21, 2025
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter4
  2. T1210 Exploitation of Remote Services3
  3. T1190 Exploit Public-Facing Application2
  4. T1068 Exploitation for Privilege Escalation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Tp-link