CVE 9.3 CRITICAL

OS command injection in multiple parameters_CVE-2025-6542

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.

AI Analysis

OS command injection vulnerability allowing remote unauthenticated attackers to execute arbitrary commands

Basic Information

ID CVE-2025-6542
Source TPLink
Published Oct 21, 2025 at 00:23
Modified Oct 21, 2025 at 01:16

Affected Product

Vendor TP-Link Systems Inc.
Product Omada gateways
Affected Versions TP-Link Systems Inc. Omada gateways 0
TP-Link Systems Inc. Festa gateways 0
TP-Link Systems Inc. Omada Pro gateways 0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor TP-Link
Product Omada gateways, Festa gateways, Omada Pro gateways

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.