CVE-2026-19586 is a critical pre-authentication OS command injection vulnerability in TP-Link Omada gateways configured to operate as an OpenVPN Server. Insufficient validation of client-supplied data during OpenVPN connection establishment permits crafted connection input to influence backend operating-system command execution before VPN authentication completes. Affected products include specified versions of ER7212PC v2, ER605 v2, ER7206 v2, ER7406 v1, ER707-M2 v1, ER7412-M2 v1, ER8411 v1, ER706W v1, ER706W-4G v2, ER706WP-4G v1, ER703WP-4G-Outdoor v1, DR3220v-4G v1, DR3650v v1, DR3650v-4G v1, ER603WP-4G-Outdoor v1, DR3150 v1, ER701-5G-Outdoor v1, and ER605W v2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file proof-of-concept repository contains a Python exploit, a bundled TP-Link CA certificate, and usage documentation. The Python entry point builds an awk-injection username, writes it with a dummy password to a temporary OpenVPN credentials file, and launches the local openvpn client against an operator-selected UDP endpoint. The malicious username closes an unquoted awk string in the target's /usr/sbin/checkpsw.sh and adds an awk BEGIN{system(...)} block, causing a supplied command to run as root before password verification. It targets the Omada SSL VPN authentication path, was stated to be tested on an ER7212PC v2 running firmware 6.1.0.19, and is not a scanner or detection-only script. The CA certificate is static firmware material; the remote target address and command are supplied at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated remote code execution vulnerability in TP-Link Omada devices that can lead to full device compromise when an OpenVPN server is running.
A pre-authentication OS command injection vulnerability in Omada gateways operating as OpenVPN servers. An unauthenticated remote attacker able to reach the enabled VPN service and initiate an OpenVPN connection may execute arbitrary commands and potentially fully compromise the device.
A critical pre-authentication OS command injection vulnerability in TP-Link Omada gateways when configured as an OpenVPN Server, allowing unauthenticated remote attackers to potentially achieve arbitrary command execution and full device compromise.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.