Back to search
CVE-2025-6541
Published: Oct 21, 2025
Modified: Oct 21, 2025
PUBLISHED
Description
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
| Vendor | Product | Versions |
|---|---|---|
TP-Link Systems Inc. | Omada gateways | affected 0 - < ER8411 1.3.3, ER7412-M2 1.1.0, ER707-M2 1.3.1, ER7206 2.2.2, ER605 2.3.1, ER706W 1.2.1, ER706W-4G 1.2.1, ER7212PC 2.1.3 |
TP-Link Systems Inc. | Festa gateways | affected 0 - < FR365 1.1.10, FR205 1.0.3, FR307 1.2.5 |
TP-Link Systems Inc. | Omada Pro gateways | affected 0 - < G36 1.1.4, G611 1.2.2 |
Weaknesses (CWE)
References
https://support.omadanetworks.com/en/document/108455/
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now