« Volver al listado

Tp-link

Tp-link Er7206 Firmware: vulnerabilidades y CVE

Tp-link Er7206 Firmware tiene 17 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE17
Últimos 12 meses8
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-9033Media (6)0.28%—20 ago 2026
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active…
CVE-2026-19683Media (6.3)0.25%—20 ago 2026
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An…
CVE-2026-19586Crítica (9.3)5.7%—20 ago 2026
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection…
CVE-2025-9290Media (6)0.22%—23 ene 2026
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and…
CVE-2025-7851Alta (8.7)0.67%—21 oct 2025
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
CVE-2025-7850Crítica (9.3)3.3%—21 oct 2025
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
CVE-2025-6542Crítica (9.3)1.0%—21 oct 2025
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
CVE-2025-6541Alta (8.6)0.69%—21 oct 2025
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
CVE-2024-21827Alta (7.2)0.88%—25 jun 2024
A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to…
CVE-2023-47618Alta (7.2)1.9%—6 feb 2024
A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to…
CVE-2023-47617Alta (7.2)3.4%—6 feb 2024
A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to…
CVE-2023-47209Alta (7.2)3.4%—6 feb 2024
A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to…
CVE-2023-47167Alta (7.2)3.4%—6 feb 2024
A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to…
CVE-2023-46683Alta (7.2)3.4%—6 feb 2024
A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request…
CVE-2023-43482Alta (7.2)3.3%—6 feb 2024
A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command…
CVE-2023-42664Alta (7.2)3.4%—6 feb 2024
A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can…
CVE-2023-36498Alta (7.2)3.4%—6 feb 2024
A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter4
  2. T1210 Exploitation of Remote Services3
  3. T1190 Exploit Public-Facing Application2
  4. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Tp-link