Tp-link
Tp-link Er7212pc Firmware: vulnerabilidades y CVE
Tp-link Er7212pc Firmware tiene 8 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses8
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9033 | Media (6) | 0.28% | — | 20 ago 2026 | An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active… |
| CVE-2026-19683 | Media (6.3) | 0.25% | — | 20 ago 2026 | A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An… |
| CVE-2026-19586 | Crítica (9.3) | 5.7% | — | 20 ago 2026 | A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection… |
| CVE-2025-9290 | Media (6) | 0.22% | — | 23 ene 2026 | An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and… |
| CVE-2025-7851 | Alta (8.7) | 0.67% | — | 21 oct 2025 | An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. |
| CVE-2025-7850 | Crítica (9.3) | 3.3% | — | 21 oct 2025 | A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. |
| CVE-2025-6542 | Crítica (9.3) | 1.0% | — | 21 oct 2025 | An arbitrary OS command may be executed on the product by a remote unauthenticated attacker. |
| CVE-2025-6541 | Alta (8.6) | 0.69% | — | 21 oct 2025 | An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.