ER7206 Firmware
16 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for ER7206 Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
ER7206 Firmware CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 4 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 3 |
| 2026-09 | 0 |
Severity
How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High12
- Medium1
Latest CVEs
The 15 most recently published vulnerabilities affecting ER7206 Firmware.
- CVE-2026-19683Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada Gateways7.4
- CVE-2026-19586Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways9.8
- CVE-2026-9033Unauthenticated Captive Portal Session Termination and Forced Logout in Omada Gateways4.3
- CVE-2025-7851Unauthorized root access via debug functionality9.8
- CVE-2025-7850Authenticated OS command execution7.2
- CVE-2025-6542OS command injection in multiple parameters9.8
- CVE-2025-6541OS command injection using information obtained from the web management interface8.8
- CVE-2024-21827A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network req...7.2
- CVE-2023-43482A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to ...7.2
- CVE-2023-36498A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP req...7.2
- CVE-2023-47167A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP requ...7.2
- CVE-2023-47209A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP re...7.2
- CVE-2023-42664A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially cra...7.2
- CVE-2023-47617A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTT...7.2
- CVE-2023-46683A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially...7.2
Product grouping is registry-driven, with AI assist and human review. How it works