Vulnerability Description
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
CVSS Score
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Er8411 Firmware | < 1.3.3 |
| Tp-Link | Er8411 | - |
| Tp-Link | Er7412-M2 Firmware | < 1.1.0 |
| Tp-Link | Er7412-M2 | - |
| Tp-Link | Er707-M2 Firmware | < 1.3.1 |
| Tp-Link | Er707-M2 | - |
| Tp-Link | Er7206 Firmware | < 2.2.2 |
| Tp-Link | Er7206 | - |
| Tp-Link | Er605 Firmware | < 2.3.1 |
| Tp-Link | Er605 | - |
| Tp-Link | Er706W Firmware | < 1.2.1 |
| Tp-Link | Er706W | - |
| Tp-Link | Er706W-4G Firmware | < 1.2.1 |
| Tp-Link | Er706W-4G | - |
| Tp-Link | Er7212Pc Firmware | < 2.1.3 |
| Tp-Link | Er7212Pc | - |
| Tp-Link | G36 Firmware | < 1.1.4 |
| Tp-Link | G36 | - |
| Tp-Link | G611 Firmware | < 1.2.2 |
| Tp-Link | G611 | - |
Related Weaknesses (CWE)
References
- https://support.omadanetworks.com/en/document/108455/Vendor Advisory
- https://www.omadanetworks.com/us/business-networking/all-omada-router/Product
- https://www.omadanetworks.com/us/business-networking/omada-pro-router-wired-routProduct
- https://www.tp-link.com/us/business-networking/soho-festa-gateway/Product
FAQ
What is CVE-2025-6542?
CVE-2025-6542 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
How severe is CVE-2025-6542?
CVE-2025-6542 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-6542?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Er8411 Firmware, Tp-Link Er8411, Tp-Link Er7412-M2 Firmware, Tp-Link Er7412-M2, Tp-Link Er707-M2 Firmware.