CVE-2025-6541
HIGHCVSS 8.6/10EPSS 0.64%
Last modified
CVE-2025-6541 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.. EPSS estimates a 0.64% chance of exploitation in the next 30 days.
Description
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Er706w Firmware | < 1.2.1 |
| Tp-Link | Er706w Firmware | 1.2.1 |
| Tp-Link | Er706w-4g Firmware | < 1.2.1 |
| Tp-Link | Er706w-4g Firmware | 1.2.1 |
| Tp-Link | Er7212pc Firmware | < 2.1.3 |
| Tp-Link | Er7212pc Firmware | 2.1.3 |
| Tp-Link | G36 Firmware | < 1.1.4 |
| Tp-Link | G36 Firmware | 1.1.4 |
| Tp-Link | G611 Firmware | < 1.2.2 |
| Tp-Link | G611 Firmware | 1.2.2 |
| Tp-Link | Fr365 Firmware | < 1.1.10 |
| Tp-Link | Fr365 Firmware | 1.1.10 |
| Tp-Link | Fr205 Firmware | < 1.0.3 |
| Tp-Link | Fr205 Firmware | 1.0.3 |
| Tp-Link | Fr307-M2 Firmware | < 1.2.5 |
| Tp-Link | Fr307-M2 Firmware | 1.2.5 |
| Tp-Link | Er8411 Firmware | < 1.3.3 |
| Tp-Link | Er8411 Firmware | 1.3.3 |
| Tp-Link | Er7412-M2 Firmware | < 1.1.0 |
| Tp-Link | Er7412-M2 Firmware | 1.1.0 |
| Tp-Link | Er707-M2 Firmware | < 1.3.1 |
| Tp-Link | Er707-M2 Firmware | 1.3.1 |
| Tp-Link | Er7206 Firmware | < 2.2.2 |
| Tp-Link | Er7206 Firmware | 2.2.2 |
| Tp-Link | Er605 Firmware | < 2.3.1 |
| Tp-Link | Er605 Firmware | 2.3.1 |
References
- https://support.omadanetworks.com/en/document/108455/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-6541?
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
How severe is CVE-2025-6541?
CVE-2025-6541 has a CVSS score of 8.6/10 (HIGH severity). The EPSS model estimates a 0.64% probability of exploitation in the next 30 days.
How do I fix CVE-2025-6541?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2025-6541?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
