All CVEs
Vulnerability intelligence

CVE-2026-19683

TP-Link Systems Inc. ER7212PC v2 CWE-319

A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path. Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.

CVSS Score
6.3
Medium
EPSS — Exploit Probability
0.3%
Riskier than 15% of all CVEs · checked 2026-10-02
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

1 article across 1 outlet · first covered Aug 21, 2026 · latest Aug 21, 2026

Coverage timeline

Related CVEs — TP-Link Systems Inc.