ZeroHour

CVE-2026-1668

CVSS 4.0
7.7 high
EPSS
<1%p60
Published
()
Modified
Description

The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when processing crafted requests. Under specific conditions, this flaw may result in unintended command execution. An unauthenticated attacker with network access to the affected interface may cause memory corruption, service instability, or information disclosure. Successful exploitation may allow remote code execution or denial-of-service.

Vendors
tp-link
Products
omada sg2005p-pd firmware, omada sg2008 firmware, omada sg2008p firmware, omada sg2016p firmware, omada sg2210mp firmware, omada sg2210p firmware, omada sg2210xmp-m2 firmware, omada sg2218 firmware, omada sg2218p firmware, omada sg2428lp firmware, omada sg2428p firmware, omada sg2452lp firmware
Weakness
CWE-20, CWE-787
Vector
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.