CVE-2025-6541 is a critical arbitrary OS command injection vulnerability affecting TP-Link Omada gateways. An authenticated attacker with web management interface access can execute arbitrary operating system commands, leading to complete compromise of the device. This vulnerability carries a CVSS score of 8.8 (High) due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog and lacking public exploit code, it has garnered significant community attention and media coverage, indicating a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.1CPE matchmatch criteria | cpe:2.3:o:tp-link:er706w_firmware:*:*:*:*:*:*:*:* | ||
1.2.1CPE matchmatch criteria | cpe:2.3:o:tp-link:er706w_firmware:1.2.1:-:*:*:*:*:*:* | ||
< 1.2.1CPE matchmatch criteria | cpe:2.3:o:tp-link:er706w-4g_firmware:*:*:*:*:*:*:*:* | ||
1.2.1CPE matchmatch criteria | cpe:2.3:o:tp-link:er706w-4g_firmware:1.2.1:-:*:*:*:*:*:* | ||
< 2.1.3CPE matchmatch criteria | cpe:2.3:o:tp-link:er7212pc_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.