CVE-2025-6541
OS command injection using information obtained from the web management interface
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
TP-Link Systems Inc. · Festa gatewaysTP-Link Systems Inc. · Omada gatewaysTP-Link Systems Inc. · Omada Pro gatewaysWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →