Dynamic DNS Vulnerability in TP-Link Omada Gateways
CVE-2026-19683

6.3MEDIUM

Key Information:

Vendor
CVE Published:
20 August 2026

What is CVE-2026-19683?

A security flaw in TP-Link Omada Gateways impacts the Dynamic DNS functionality, where authentication credentials are transmitted without encryption during communication with third-party DDNS services. This vulnerability allows attackers who can monitor or manipulate traffic on the relevant network path to potentially acquire sensitive authentication details or disrupt DDNS update operations. If exploited, attackers may gain unauthorized access to DDNS management features or alter DNS records tied to the affected deployment, posing significant risks to network integrity.

Affected Version(s)

DR3150 v1 0 < 1.0.1 Build 20260722 Rel.16854

DR3220v-4G v1 0 < 1.2.0 Build 20260630 Rel.82652

DR3650v v1 0 < 1.2.0 Build 20260630 Rel.83311

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.