CVE-2025-7851
Published Oct 21, 2025An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
- evidence mentions
- 2
- Buzz score
- 17.5
Vendor/product archive
4 CVEs tagged to tp-link / fr365_firmware — 2 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.