Aller au contenu

Fiche vulnérabilité

CVE-2026-1668 : faille critique tp-link omada sg2005p-pd firmware (CVSS 9.8)

Description

The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when processing crafted requests. Under specific conditions, this flaw may result in unintended command execution.<br>An unauthenticated attacker with network access to the affected interface may cause memory corruption, service instability, or information disclosure. Successful exploitation may allow remote code execution or denial-of-service.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
13 mars 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • tp-link omada sg2005p-pd firmware
  • tp-link omada sg2008 firmware
  • tp-link omada sg2008p firmware
  • tp-link omada sg2016p firmware
  • tp-link omada sg2210mp firmware
  • tp-link omada sg2210p firmware
  • tp-link omada sg2210xmp-m2 firmware
  • tp-link omada sg2218 firmware
  • tp-link omada sg2218p firmware
  • tp-link omada sg2428lp firmware
  • tp-link omada sg2428p firmware
  • tp-link omada sg2452lp firmware
  • tp-link omada sg3210 firmware
  • tp-link omada sg3210xhp-m2 firmware
  • tp-link omada sg3210x-m2 firmware
  • tp-link omada sg3218xp-m2 firmware
  • tp-link omada sg3428 firmware
  • tp-link omada sg3428mp firmware
  • tp-link omada sg3428x firmware
  • tp-link omada sg3428xf firmware

Références

Rechercher une autre vulnérabilité dans la base CVE