HIGH
OS command injection using information obtained from the web management interface
Published Oct 21, 2025
8.6
HIGHCVSS 4.0
EPSS 0.69%
Description
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
Affected products
-
- Version 0StatusaffectedConstraints<FR365 1.1.10, FR205 1.0.3, FR307 1.2.5
- Version
-
- Version 0StatusaffectedConstraints<G36 1.1.4, G611 1.2.2
- Version
-
- Version 0StatusaffectedConstraints<ER8411 1.3.3, ER7412-M2 1.1.0, ER707-M2 1.3.1, ER7206 2.2.2, ER605 2.3.1, ER706W 1.2.1, ER706W-4G 1.2.1, ER7212PC 2.1.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| TP-Link Systems Inc. | Festa gateways | unaffected |
| ||||||
| TP-Link Systems Inc. | Omada Pro gateways | unaffected |
| ||||||
| TP-Link Systems Inc. | Omada gateways | n/a |
|
Configuration 1
AND
OR
- < 1.2.1
- 1.2.1
Configuration 2
AND
OR
- < 1.2.1
- 1.2.1
Configuration 3
AND
OR
- < 2.1.3
- 2.1.3
Configuration 4
AND
OR
- < 1.1.4
- 1.1.4
Configuration 5
AND
OR
- < 1.2.2
- 1.2.2
Configuration 6
AND
OR
- < 1.1.10
- 1.1.10
Configuration 7
AND
OR
- < 1.0.3
- 1.0.3
Configuration 8
AND
OR
- < 1.2.5
- 1.2.5
Configuration 9
AND
OR
- < 1.3.3
- 1.3.3
Configuration 10
AND
OR
- < 1.1.0
- 1.1.0
Configuration 11
AND
OR
- < 1.3.1
- 1.3.1
Configuration 12
AND
OR
- < 2.2.2
- 2.2.2
Configuration 13
AND
OR
- < 2.3.1
- 2.3.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-35118 Advisory
- https://support.omadanetworks.com/en/document/108455/ vendor-advisoryVendor Advisory
- https://www.omadanetworks.com/us/business-networking/all-omada-router/ product
- https://www.omadanetworks.com/us/business-networking/omada-pro-router-wired-router/ product
- https://www.tp-link.com/us/business-networking/soho-festa-gateway/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-35118 | Advisory | |
| https://support.omadanetworks.com/en/document/108455/ | vendor-advisoryVendor Advisory | |
| https://www.omadanetworks.com/us/business-networking/all-omada-router/ | product | |
| https://www.omadanetworks.com/us/business-networking/omada-pro-router-wired-router/ | product | |
| https://www.tp-link.com/us/business-networking/soho-festa-gateway/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TPLink
Published Oct 21, 2025
Updated Oct 21, 2025
Reserved Jun 23, 2025
Link CVE-2025-6541
CISA Vulnrichment
Updated Oct 21, 2025
ENISA EUVD
EUVD-2025-35118 Assigner TPLink
Published Oct 21, 2025
Updated Oct 21, 2025
Exploited since n/a
Link EUVD-2025-35118