CVE detail
CVE-2025-7851
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
TP-Link warns of critical flaws in Omada gateways across ER, G, and FR models. Users should update firmware immediately to stay secure. TP-Link is warning users of critical flaws impacting its Omada gateway devices. The Taiwanese company published two security advisories this week, outlining four vulnerabilities that impacts more than a dozen products across the […]
newssecurityaffairs.comOct 22, 2025, 5:56 PMOne of the flaws can be exploited by remote unauthenticated attackers for arbitrary command execution.
newswww.securityweek.comOct 22, 2025, 1:41 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-7850CVSS 9.3 · Critical
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
- CVE-2025-6542CVSS 9.3 · Critical
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
- CVE-2025-6541CVSS 8.6 · High
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
- CVE-2025-9290CVSS 6.0 · Medium
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requ…
- CVE-2024-21827CVSS 7.2 · High
A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted ser…
- CVE-2023-47618CVSS 7.2 · High
A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specia…