Vulnerability Description
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Fr307-M2 Firmware | < 1.2.5 |
| Tp-Link | Fr307-M2 | - |
| Tp-Link | Fr205 Firmware | < 1.0.3 |
| Tp-Link | Fr205 | - |
| Tp-Link | Fr365 Firmware | < 1.1.10 |
| Tp-Link | Fr365 | - |
| Tp-Link | G611 Firmware | < 1.2.2 |
| Tp-Link | G611 | - |
| Tp-Link | G36 Firmware | < 1.1.4 |
| Tp-Link | G36 | - |
| Tp-Link | Er7212Pc Firmware | < 2.1.3 |
| Tp-Link | Er7212Pc | - |
| Tp-Link | Er706W-4G Firmware | < 1.2.1 |
| Tp-Link | Er706W-4G | - |
| Tp-Link | Er706W Firmware | < 1.2.1 |
| Tp-Link | Er706W | - |
| Tp-Link | Er605 Firmware | < 2.3.1 |
| Tp-Link | Er605 | - |
| Tp-Link | Er7206 Firmware | < 2.2.2 |
| Tp-Link | Er7206 | - |
Related Weaknesses (CWE)
References
- https://support.omadanetworks.com/en/document/108456/Vendor Advisory
- https://www.forescout.com/blog/new-tp-link-router-vulnerabilities-a-primer-on-ro
- https://www.omadanetworks.com/us/business-networking/all-omada-router/Product
- https://www.omadanetworks.com/us/business-networking/omada-pro-router-wired-routProduct
- https://www.tp-link.com/us/business-networking/soho-festa-gateway/Product
FAQ
What is CVE-2025-7851?
CVE-2025-7851 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
How severe is CVE-2025-7851?
CVE-2025-7851 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-7851?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Fr307-M2 Firmware, Tp-Link Fr307-M2, Tp-Link Fr205 Firmware, Tp-Link Fr205, Tp-Link Fr365 Firmware.