Impact
The vulnerability allows an attacker who can observe or manipulate traffic between a TP‑Link Omada Gateway and a third‑party Dynamic DNS service to capture authentication credentials transmitted over an unencrypted channel. With these credentials, the attacker may authenticate to the DDNS management interface, access sensitive information, or modify the DNS records associated with the deployment.
Affected Systems
Affected devices include a range of TP‑Link Omada Gateway models such as the DR3150, DR3220v‑4G, DR3650v, DR3650v‑4G, ER603WP‑4G‑Outdoor, ER605, ER605W, ER701‑5G‑Outdoor, ER703WP‑4G‑Outdoor, ER706W, ER706W‑4G, ER706WP‑4G, ER707‑M2, ER7206, ER7212PC, ER8411, ER7406, and ER7412‑M2, all listed at firmware version 1 or 2.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity. With no EPSS score available, the likelihood of exploitation remains uncertain but could be higher in environments where external DDNS traffic is common and network visibility is available. The vulnerability is not listed in CISA KEV, suggesting no known large‑scale exploitation yet. An attacker still requires the DDNS feature to be enabled and must be able to capture or alter traffic between the gateway and the external DDNS service.
OpenCVE Enrichment