Tp-link
Tp-link Er605 Firmware: vulnerabilities and CVEs
Tp-link Er605 Firmware has 8 published vulnerabilities, 8 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs8
Last 12 months8
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9033 | Medium (6) | 0.28% | — | Aug 20, 2026 | An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active… |
| CVE-2026-19683 | Medium (6.3) | 0.25% | — | Aug 20, 2026 | A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An… |
| CVE-2026-19586 | Critical (9.3) | 5.7% | — | Aug 20, 2026 | A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection… |
| CVE-2025-9290 | Medium (6) | 0.22% | — | Jan 23, 2026 | An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and… |
| CVE-2025-7851 | High (8.7) | 0.67% | — | Oct 21, 2025 | An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. |
| CVE-2025-7850 | Critical (9.3) | 3.3% | — | Oct 21, 2025 | A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. |
| CVE-2025-6542 | Critical (9.3) | 1.0% | — | Oct 21, 2025 | An arbitrary OS command may be executed on the product by a remote unauthenticated attacker. |
| CVE-2025-6541 | High (8.6) | 0.69% | — | Oct 21, 2025 | An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.