CVE-2026-1668
Received
Received - Intake
Out-of-Bounds Access in Omada Switch Web Interface Enables RCE
Publication date: 2026-03-13
Last updated on: 2026-04-02
Assigner: TPLink
Description
Description
The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when processing crafted requests. Under specific conditions, this flaw may result in unintended command execution.<br>An unauthenticated attacker with network access to the affected interface may cause memory corruption, service instability, or information disclosure. Successful exploitation may allow remote code execution or denial-of-service.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tp-link | omada_sg2005p-pd_firmware | From 1.0.0 (inc) to 1.0.19 (exc) |
| tp-link | omada_sg2008_firmware | From 4.20.0 (inc) to 4.20.17 (exc) |
| tp-link | omada_sg2008_firmware | From 4.30.0 (inc) to 4.30.1 (exc) |
| tp-link | omada_sg2008p_firmware | From 3.20.0 (inc) to 3.20.17 (exc) |
| tp-link | omada_sg2008p_firmware | From 3.30.0 (inc) to 3.30.1 (exc) |
| tp-link | omada_sg2016p_firmware | From 1.20.0 (inc) to 1.20.17 (exc) |
| tp-link | omada_sg2016p_firmware | From 1.30.0 (inc) to 1.30.1 (exc) |
| tp-link | omada_sg2210mp_firmware | From 4.20.0 (inc) to 4.20.18 (exc) |
| tp-link | omada_sg2210mp_firmware | From 5.0.0 (inc) to 5.0.15 (exc) |
| tp-link | omada_sg2210mp_firmware | From 5.20.0 (inc) to 5.20.1 (exc) |
| tp-link | omada_sg2210p_firmware | From 5.20.0 (inc) to 5.20.18 (exc) |
| tp-link | omada_sg2210p_firmware | From 5.30.0 (inc) to 5.30.1 (exc) |
| tp-link | omada_sg2210xmp-m2_firmware | From 1.0.0 (inc) to 1.0.19 (exc) |
| tp-link | omada_sg2218_firmware | From 1.20.0 (inc) to 1.20.17 (exc) |
| tp-link | omada_sg2218_firmware | From 1.30.0 (inc) to 1.30.1 (exc) |
| tp-link | omada_sg2218p_firmware | From 1.20.0 (inc) to 1.20.17 (exc) |
| tp-link | omada_sg2218p_firmware | From 2.0.0 (inc) to 2.0.14 (exc) |
| tp-link | omada_sg2218p_firmware | From 2.20.0 (inc) to 2.20.2 (exc) |
| tp-link | omada_sg2428lp_firmware | From 1.0.0 (inc) to 1.0.13 (exc) |
| tp-link | omada_sg2428p_firmware | From 5.20.0 (inc) to 5.20.20 (exc) |
| tp-link | omada_sg2428p_firmware | From 5.30.0 (inc) to 5.30.16 (exc) |
| tp-link | omada_sg2452lp_firmware | From 1.0.0 (inc) to 1.0.13 (exc) |
| tp-link | omada_sg3210_firmware | From 3.20.0 (inc) to 3.20.17 (exc) |
| tp-link | omada_sg3210_firmware | From 3.30.0 (inc) to 3.30.1 (exc) |
| tp-link | omada_sg3210xhp-m2_firmware | From 3.0.0 (inc) to 3.0.21 (exc) |
| tp-link | omada_sg3210x-m2_firmware | From 1.20.0 (inc) to 1.20.1 (exc) |
| tp-link | omada_sg3218xp-m2_firmware | From 1.0.0 (inc) to 1.0.19 (exc) |
| tp-link | omada_sg3428_firmware | From 2.30.0 (inc) to 2.30.16 (exc) |
| tp-link | omada_sg3428_firmware | From 2.40.0 (inc) to 2.40.1 (exc) |
| tp-link | omada_sg3428mp_firmware | From 6.20.0 (inc) to 6.20.20 (exc) |
| tp-link | omada_sg3428mp_firmware | From 6.30.0 (inc) to 6.30.1 (exc) |
| tp-link | omada_sg3428x_firmware | From 1.30.0 (inc) to 1.30.17 (exc) |
| tp-link | omada_sg3428x_firmware | From 1.40.0 (inc) to 1.40.1 (exc) |
| tp-link | omada_sg3428xf_firmware | From 1.20.0 (inc) to 1.20.16 (exc) |
| tp-link | omada_sg3428xf_firmware | From 1.30.0 (inc) to 1.30.1 (exc) |
| tp-link | omada_sg3428x-m2_firmware | From 1.20.0 (inc) to 1.20.18 (exc) |
| tp-link | omada_sg3428xmp_firmware | From 3.20.0 (inc) to 3.20.21 (exc) |
| tp-link | omada_sg3428xmp_firmware | From 3.30.0 (inc) to 3.30.1 (exc) |
| tp-link | omada_sg3428xmpp_firmware | From 1.0.0 (inc) to 1.0.16 (exc) |
| tp-link | omada_sg3428xmpp_firmware | From 1.20.0 (inc) to 1.20.1 (exc) |
| tp-link | omada_sg3428xpp-m2_firmware | From 1.20.0 (inc) to 1.20.19 (exc) |
| tp-link | omada_sg3452_firmware | From 1.20.0 (inc) to 1.20.17 (exc) |
| tp-link | omada_sg3452_firmware | From 1.30.0 (inc) to 1.30.1 (exc) |
| tp-link | omada_sg3452p_firmware | From 3.30.0 (inc) to 3.30.17 (exc) |
| tp-link | omada_sg3452p_firmware | From 3.40.0 (inc) to 3.40.1 (exc) |
| tp-link | omada_sg3452x_firmware | From 1.20.0 (inc) to 1.20.18 (exc) |
| tp-link | omada_sg3452x_firmware | From 1.30.0 (inc) to 1.30.1 (exc) |
| tp-link | omada_sg3452xmpp_firmware | From 1.0.0 (inc) to 1.0.15 (exc) |
| tp-link | omada_sg3452xp_firmware | From 2.20.0 (inc) to 2.20.20 (exc) |
| tp-link | omada_sg3452xp_firmware | From 2.30.0 (inc) to 2.30.1 (exc) |
| tp-link | omada_sl2428p_firmware | From 6.20.0 (inc) to 6.20.18 (exc) |
| tp-link | omada_sx3008f_firmware | From 1.20.0 (inc) to 1.20.12 (exc) |
| tp-link | omada_sx3016f_firmware | From 1.20.0 (inc) to 1.20.16 (exc) |
| tp-link | omada_sx3016f_firmware | From 1.30.0 (inc) to 1.30.1 (exc) |
| tp-link | omada_sx3032f_firmware | From 1.0.0 (inc) to 1.0.15 (exc) |
| tp-link | omada_sx3206hpp_firmware | From 1.20.0 (inc) to 1.20.12 (exc) |
| tp-link | omada_sx3832_firmware | From 1.0.0 (inc) to 1.0.12 (exc) |
| tp-link | omada_sx3832mpp_firmware | From 1.0.0 (inc) to 1.0.11 (exc) |
| tp-link | omada_tl-sg2428p_firmware | From 4.0.0 (inc) to 4.0.26 (exc) |
| tp-link | omada_tl-sg3428mp_firmware | From 5.0.0 (inc) to 5.0.25 (exc) |
| tp-link | omada_tl-sg3452p_firmware | From 3.0.0 (inc) to 3.0.22 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
| CWE-20 | The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. |