PT-2025-42823 · Unknown · Web Management Interface

Published

2025-10-21

·

Updated

2025-11-26

·

CVE-2025-6542

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TP-Link Omada Gateway (affected versions not specified)
Description An arbitrary OS command may be executed by a remote attacker. An unauthenticated attacker can potentially execute commands on the system. The issue allows for remote command injection in multiple parameters and through the web management interface. This could allow attackers to gain full system control.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-13230
CVE-2025-6542

Affected Products

Web Management Interface