CVE Feed

    Dashboard / CVE / CVE-2026-19683

    CVE-2026-19683

    A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path.  Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.

    Published:Aug 20, 2026
    Last Modified:Aug 21, 2026
    EPS:Aug 20, 2026
    EPSS Score:0.00292
    CVSS Score:6.3

    Affected Products

    Vendor
    Tp-link
    Product
    Dr3150 V1
    Vendor
    Tp-link
    Product
    Dr3220v-4g V1
    Vendor
    Tp-link
    Product
    Dr3650v-4g V1
    Vendor
    Tp-link
    Product
    Dr3650v V1
    Vendor
    Tp-link
    Product
    Er603wp-4g-outdoor V1
    Vendor
    Tp-link
    Product
    Er605 V2
    Vendor
    Tp-link
    Product
    Er605w V2
    Vendor
    Tp-link
    Product
    Er701-5g-outdoor V1
    Vendor
    Tp-link
    Product
    Er703wp-4g-outdoor V1
    Vendor
    Tp-link
    Product
    Er706w-4g V2
    Vendor
    Tp-link
    Product
    Er706w V1
    Vendor
    Tp-link
    Product
    Er706wp-4g V1
    Vendor
    Tp-link
    Product
    Er707-m2 V1
    Vendor
    Tp-link
    Product
    Er7206 V2
    Vendor
    Tp-link
    Product
    Er7212pc V2
    Vendor
    Tp-link
    Product
    Er8411 V1
    Vendor
    Tp-link
    Product
    V1
    Vendor
    Tp-link Systems Inc
    Product
    Er7406 V1
    Vendor
    Tp-link Systems Inc
    Product
    Er7412-m2 V1

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High