CSIRT-ITA said TP-Link Omada Gateway models have multiple firmware-level remote code execution flaws, including one rated critical, and the vendor has released fixed firmware for a long list of device-specific builds. The affected set includes ER, DR, and outdoor models such as ER7212PC, ER605, ER7206, ER7406, ER707-M2, ER7412-M2, ER8411, ER706W, and DR3150.
The issue is spread across separate model/version pairs, so the hard part is not one universal update but matching each gateway to its own fixed build. In plain terms, a fleet can still contain exposed appliances even after some Omada devices are patched if another model or branch unit was missed.
For teams running mixed Omada fleets, the exposure now sits in inventory gaps as much as in the firmware itself: any gateway left on an older build remains in scope until its specific replacement version is installed. There is no exploitation signal here, but the advisory makes the upgrade matrix itself the operational risk.