Impact
A pre‑authentication OS command injection flaw exists in Omada gateways that run the OpenVPN Server. During the VPN connection setup an attacker may send crafted input that is not properly validated, causing back‑end command execution before authentication. The resulting remote code execution can give an attacker full control over the affected device.
Affected Systems
TP‑Link Omada gateways, including DR3150 v1, DR3220v‑4G v1, DR3650v v1, DR3650v‑4G v1, ER603WP‑4G‑Outdoor v1, ER605 v2, ER605W v2, ER701‑5G‑Outdoor v1, ER703WP‑4G‑Outdoor v1, ER706W v1, ER706W‑4G v2, ER706WP‑4G v1, ER707‑M2 v1, ER7206 v2, ER7212PC v2, ER8411 v1, ER7406 v1, and ER7412‑M2 v1.
Risk and Exploitability
The flaw carries a CVSS score of 9.3, classifying it as critically severe. The EPSS score is 5% and it is not listed in the CISA KEV catalogue, although the lack of data does not diminish the potential for exploitation. An attacker only needs to send a malicious OpenVPN packet to a device that has the OpenVPN Server feature enabled and exposed to the internet. Because the command injection occurs before authentication, no credentials are required. The upstream knowledge of the flaw means that, if a patch is not applied, the vulnerability remains a high‑risk vector for remote compromise.
OpenCVE Enrichment