CVE-2026-19683

HIGHCVSS 7.4/10EPSS 0.29%

Last modified

CVE-2026-19683 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. EPSS estimates a 0.29% chance of exploitation in the next 30 days.

Description

A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path.  Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.

Metrics

Weakness Enumeration

Affected Software

VendorProductVersions
Tp-LinkEr7212pc Firmware< 2.4.3
Tp-LinkEr605 Firmware< 2.4.4
Tp-LinkEr7206 Firmware< 2.3.5
Tp-LinkEr7406 Firmware< 1.3.4
Tp-LinkEr707-M2 Firmware< 1.4.4
Tp-LinkEr7412-M2 Firmware< 1.2.0
Tp-LinkEr8411 Firmware< 1.4.1
Tp-LinkEr706w Firmware< 1.2.11
Tp-LinkEr706w-4g Firmware< 1.2.6
Tp-LinkEr706w-4g Firmware< 2.1.11
Tp-LinkEr706wp-4g Firmware< 1.1.11
Tp-LinkEr703wp-4g-Outdoor Firmware< 1.1.7
Tp-LinkDr3220v-4g Firmware< 1.2.0
Tp-LinkDr3650v Firmware< 1.2.0
Tp-LinkDr3650v-4g Firmware< 1.2.0
Tp-LinkEr603wp-4g-Outdoor Firmware< 1.0.2
Tp-LinkDr3150 Firmware< 1.0.1
Tp-LinkEr701-5g-Outdoor Firmware< 1.0.3
Tp-LinkEr605w Firmware< 2.0.4

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2026-19683?
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path.  Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.
How severe is CVE-2026-19683?
CVE-2026-19683 has a CVSS score of 7.4/10 (HIGH severity). The EPSS model estimates a 0.29% probability of exploitation in the next 30 days.
How do I fix CVE-2026-19683?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-19683?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST