logo

TP-Link warns of critical command injection flaw in Omada gateways

ID: bf1d1bd9-22f4-57cc-ac59-8e6207594850

STIX ID: report--bf1d1bd9-22f4-57cc-ac59-8e6207594850

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-10-21

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

TP-Link warns of multiple critical command injection vulnerabilities in Omada gateway devices — notably CVE-2025-6542 (remote unauthenticated, CVSS 9.3) and CVE-2025-6541 (auth required) — that permit arbitrary OS commands; the vendor published fixed firmware for 13 affected models and urges users to update and verify configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.