Skip to content
COOEY

EXPOSURES › CVE-2026-19586

CVE-2026-19586

CRITICAL
DETAIL
SourceNVD · cve Published2026-08-20 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-19586 ↗
⚡ RCE SHAME 85/100 rceunpatchedexploited-in-wild

TP-Link Omada gateways with OpenVPN Server enabled suffer a pre-auth OS command injection flaw allowing unauthenticated remote attackers to execute arbitrary commands.

An unauthenticated remote attacker can exploit this pre-authentication OS command injection vulnerability in TP-Link Omada gateways configured as OpenVPN servers to execute arbitrary commands before authentication completes. This failure is critical for DIB organizations because it enables remote code execution without prior authentication, directly violating secure configuration and access control requirements under NIST 800-171. Organizations must immediately disable the OpenVPN Server feature or patch affected firmware to prevent full device compromise and potential supply-chain attacks.

Shame score — A pre-authentication command injection flaw in a widely deployed networking product that allows unauthenticated remote attackers to execute arbitrary commands before authentication, representing a severe avoidable security failure.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.  Successful exploitation may allow arbitrary command execution, potentially leading to full compromise of the affected device.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.