← Vulnerability feed

Vulnerability record · CVE-2024-21827 · published 25 June 2024

CVE-2024-21827: Tp-link er7206 firmware vulnerability

Tp Link · Er7206 Firmware

A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

7.2 CVSS 3.1 High EPSS 0.87% · top 42.8% CWE-489 · CWE-489
7.2CVSS 3.1 base score
0.87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-21827 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-19586Tp-link er7212pc firmware os command injection vulnerabilityA pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insuf…EPSS 5.7%9.3CVE-2025-6542Tp-link er8411 firmware os command injection vulnerabilityAn arbitrary OS command may be executed on the product by a remote unauthenticated attacker.EPSS 1.0%9.3CVE-2025-7850Tp-link er8411 firmware os command injection vulnerabilityA command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.EPSS 3.3%8.7CVE-2025-7851Tp-link fr307-m2 firmware improper privilege management vulnerabilityAn attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.EPSS 0.67%8.6CVE-2025-6541Tp-link er706w firmware os command injection vulnerabilityAn arbitrary OS command may be executed on the product by the user who can log in to the web management interface.EPSS 0.68%7.2CVE-2023-47618Tp-link er7206 firmware os command injection vulnerabilityA post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 buil…EPSS 1.9%7.2CVE-2023-46683Tp-link er7206 firmware os command injection vulnerabilityA post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Rou…EPSS 3.4%7.2CVE-2023-47167Tp-link er7206 firmware os command injection vulnerabilityA post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 2…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2024-21827), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.