ZeroHour

Vulnerabilities

9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-19586
+2 in the same advisory: …19683 …9033
Pre-auth OS command injection in TP-Link Omada gateways via OpenVPN Server

CVE-2026-19586 is a pre-authentication OS command injection flaw (CWE-78) in TP-Link Omada business gateways when they are configured to operate as an OpenVPN Server, caused by insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker who can reach the VPN service can send specially crafted input during a connection attempt to influence backend command execution before authentication completes, gaining arbitrary command execution and potentially full compromise of the gateway, which typically sits at the network edge controlling routing and VPN for the whole site. Affected organizations are those running any of the listed Omada gateway models with the OpenVPN Server feature enabled and reachable by the attacker. TP-Link rates the issue critical (CVSS 4.0 base score 9.3). A public technical write-up/PoC exists and EPSS assigns a 5.7% probability of exploitation within 30 days (93rd percentile), but exploitation has not yet been confirmed in the wild and the flaw is not in CISA KEV.

Do: Update all listed Omada gateway models to the latest firmware per TP-Link's security advisory (fixed version numbers are not specified in the available data, so check the advisory for affected/fixed ranges). Until patched, disable OpenVPN Server or restrict access to the VPN service (e.g., firewall/ACL rules limiting UDP 1194 to trusted sources). Inventory your estate for these gateway models, confirm whether OpenVPN Server is enabled and reachable, and review VPN logs for anomalous connection attempts.

9.3
group max
6% PoC
  • TP-Link Omada ER7212PC gateway firmware
  • TP-Link Omada ER605 gateway firmware
  • TP-Link Omada ER605W gateway firmware
  • +9 more
large~10,000-100,000 internet-exposed OpenVPN-enabled gateways, out of a much larger deployed base of these SMB gateway models
CVE-2026-8619
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper h

An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated HTTP request to trigger a crash of the HTTP service process. Successful exploitation may cause the HTTP service to crash, making the web management interface and HTTP-dependent functionality temporarily unavailable.

NVD description · AI analysis pending
7.1<1%
  • tp-link tl-mr100 firmware
  • tp-link archer mr600 firmware
  • tp-link tl-mr150 firmware
  • +1 more
CVE-2026-75616
An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operati

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device compromise. Successful exploitation may allow arbitrary command execution with elevated privileges, compromising the confidentiality, integrity, and availability of the affected device and network traffic passing through it.

NVD description · AI analysis pending
8.53%
  • tp-link archer c20 firmware
CVE-2026-75618
+1 in the same advisory: …75619
Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service.

Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video streaming functionality and cause a temporary denial-of-service condition.

NVD description · AI analysis pending
7.1
group max
<1%
  • tp-link tapo c100 firmware
  • tp-link tapo c101 firmware
CVE-2026-15316
Unauthenticated Input Validation DoS in TP-Link Tapo C200 v5 Configuration Service

CVE-2026-15316 is an improper input validation flaw (CWE-20) in the configuration service of the TP-Link Tapo C200 camera (v5) that processes encrypted credential data. An attacker on an adjacent network can send oversized ciphertext values with no authentication required; insufficient validation causes exception-handling failures that crash or restart the device. The impact is a denial-of-service condition that temporarily disrupts HTTPS management and monitoring until the service recovers, with no confidentiality or integrity impact per the CVSS vector. Anyone running a Tapo C200 v5 camera is affected, though exploitation requires the attacker to reach the device's network (adjacent-network vector). No public proof-of-concept exists, the issue is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation within 30 days.

Do: Check your Tapo C200 firmware version in the Tapo app and apply TP-Link's firmware update for v5 when released. In the meantime, keep the camera's management interface off guest/WAN-exposed network segments and restrict it to trusted LANs, since the attack is unauthenticated and adjacent-network. Note that related reporting on TP-Link camera flaws (including eavesdropping issues) makes prompt patching of Tapo devices generally advisable.

7.1<1%
  • TP-Link Tapo C200 firmware v5
masslikely millions of consumer installations (C200 is a top-selling budget Wi-Fi camera; only v5 units affected)
CVE-2026-15315
Authentication Bypass via Challenge Validation Flaw in TP-Link Tapo C120/C200 Cameras

TP-Link Tapo C120 (v1) and Tapo C200 (v5) cameras contain an improper authentication vulnerability (CWE-287) in the login authentication verification module, rated high severity at CVSS 4.0 8.7. An attacker already present on the same local network as the camera (adjacent-network attack vector) can exploit weak validation of challenge parameters during the login handshake to bypass normal authentication and obtain administrative session tokens. With these tokens, the attacker can perform privileged management actions, gain unauthorized administrative access to the camera, and temporarily disrupt device services, causing a denial-of-service condition. All consumer and small-business deployments of these specific camera hardware/firmware versions are affected. A public proof-of-concept exists on GitHub, but EPSS is low (0.3% in 30 days) and the flaw is not in the CISA KEV catalog, so exploitation in the wild is not currently observed.

Do: Check the hardware/firmware version of any Tapo C120 or C200 units in your environment (Tapo app > device settings > firmware) and apply the latest firmware TP-Link publishes for these models as soon as a fix is available, monitoring TP-Link's security advisory page. Because exploitation requires local network access, place cameras on a segregated IoT/guest VLAN that cannot reach trusted internal segments, and verify camera accounts, bindings, and recorded footage for signs of unauthorized administrative access.

8.7<1% PoC
  • tp-link tapo c120 firmware v1
  • tp-link tapo c200 firmware v5
massplausibly over 1 million deployed units across both models (order of magnitude, clearly an estimate)