9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
AI Analysis
OS command injection vulnerability allowing remote unauthenticated attackers to execute arbitrary commands
Basic Information
ID
CVE-2025-6542
Source
TPLink
Published
Oct 21, 2025 at 00:23
Modified
Oct 21, 2025 at 01:16
Affected Product
Vendor
TP-Link Systems Inc.
Product
Omada gateways
Affected Versions
TP-Link Systems Inc. Omada gateways 0
TP-Link Systems Inc. Festa gateways 0
TP-Link Systems Inc. Omada Pro gateways 0
TP-Link Systems Inc. Festa gateways 0
TP-Link Systems Inc. Omada Pro gateways 0
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
TP-Link
Product
Omada gateways, Festa gateways, Omada Pro gateways