Fiche vulnérabilité
CVE-2026-19683 : faille élevée tp-link er7212pc firmware (CVSS 7.4)
Description
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path. Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.
En bref
- Sévérité
- Élevée (CVSS 7.4)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 20 août 2026
- Dernière mise à jour
- 8 sept. 2026
Produits concernés
- tp-link er7212pc firmware
- tp-link er605 firmware
- tp-link er7206 firmware
- tp-link er7406 firmware
- tp-link er707-m2 firmware
- tp-link er7412-m2 firmware
- tp-link er8411 firmware
- tp-link er706w firmware
- tp-link er706w-4g firmware
- tp-link er706wp-4g firmware
- tp-link er703wp-4g-outdoor firmware
- tp-link dr3220v-4g firmware
- tp-link dr3650v firmware
- tp-link dr3650v-4g firmware
- tp-link er603wp-4g-outdoor firmware
- tp-link dr3150 firmware
- tp-link er701-5g-outdoor firmware
- tp-link er605w firmware