CRITICAL🇵🇱 Wersja polska

CVE-2025-6542

CVSS 9.3v4.0pub. 2025-10-21upd. 2025-10-24

An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.

🤖 AI Analysis
How it works

An attacker sends a specially crafted network request to the vulnerable device without needing any authentication credentials. The injected command (command injection) is then executed by the device's operating system with the privileges of the process handling the request. The vulnerability results from insufficient validation or sanitization of input data passed to system functions, classifying it as CWE-78 (Improper Neutralization of Special Elements used in an OS Command).

Impact

An attacker can execute arbitrary commands at the operating system level on the device, which in practice means complete takeover of the router — including the ability to change network configuration, intercept network traffic, install backdoors, and use the device as an entry point to the internal network.

Mitigation & patch

Patches available from the manufacturer must be applied immediately in accordance with the document published at https://support.omadanetworks.com/en/document/108455/. Additionally, it is recommended to restrict access to the device management interface only to trusted IP addresses and prevent exposure of the administrative panel to untrusted networks (e.g., the Internet).

Who is affected

TP-Link devices: FR307-M2 (firmware), G36, ER707-M2, ER706W (firmware), ER7206 (firmware) — specific versions of vulnerable software indicated in the manufacturer's references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Tp Link Er605

    HW
    Tp-Link
    all versions
  • Tp Link Er605 Firmware

    OS
    Tp-Link
    2.3.1< 2.3.1
  • Tp Link Er706w

    HW
    Tp-Link
    all versions
  • Tp Link Er706w 4g

    HW
    Tp-Link
    all versions
  • Tp Link Er706w 4g Firmware

    OS
    Tp-Link
    1.2.1< 1.2.1
  • Tp Link Er706w Firmware

    OS
    Tp-Link
    1.2.1< 1.2.1
  • Tp Link Er707 M2

    HW
    Tp-Link
    all versions
  • Tp Link Er707 M2 Firmware

    OS
    Tp-Link
    1.3.1< 1.3.1
  • Tp Link Er7206

    HW
    Tp-Link
    all versions
  • Tp Link Er7206 Firmware

    OS
    Tp-Link
    2.2.2< 2.2.2
  • Tp Link Er7212pc

    HW
    Tp-Link
    all versions
  • Tp Link Er7212pc Firmware

    OS
    Tp-Link
    2.1.3< 2.1.3
  • Tp Link Er7412 M2

    HW
    Tp-Link
    all versions
  • Tp Link Er7412 M2 Firmware

    OS
    Tp-Link
    1.1.0< 1.1.0
  • Tp Link Er8411

    HW
    Tp-Link
    all versions
  • Tp Link Er8411 Firmware

    OS
    Tp-Link
    1.3.3< 1.3.3
  • Tp Link Fr205

    HW
    Tp-Link
    all versions
  • Tp Link Fr205 Firmware

    OS
    Tp-Link
    1.0.3< 1.0.3
  • Tp Link Fr307 M2

    HW
    Tp-Link
    all versions
  • Tp Link Fr307 M2 Firmware

    OS
    Tp-Link
    1.2.5< 1.2.5
  • Tp Link Fr365

    HW
    Tp-Link
    all versions
  • Tp Link Fr365 Firmware

    OS
    Tp-Link
    1.1.10< 1.1.10
  • Tp Link G36

    HW
    Tp-Link
    all versions
  • Tp Link G36 Firmware

    OS
    Tp-Link
    1.1.4< 1.1.4
  • Tp Link G611

    HW
    Tp-Link
    all versions
  • Tp Link G611 Firmware

    OS
    Tp-Link
    1.2.2< 1.2.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassCommand Injection
CWE
References

Related vulnerabilities

CVE-2026-19586CRITICAL9.3same product

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to op...

CVE-2025-7850CRITICAL9.3PL ✓same product

Command injection w bramkach Omada (TP-Link) po uwierzytelnieniu admina

CVE-2025-7851HIGH8.7same product

An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gate...

CVE-2025-6541HIGH8.6same product

An arbitrary OS command may be executed on the product by the user who can log in to the web management interf...

CVE-2024-21827HIGH7.2same product

A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigab...