CVE-2025-7851

CRITICAL WAF: Low
CVSS 9.8 Published: 2025-10-21
CWE-269

An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.

WAF Coverage Analysis

Improper Privilege Management Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
tp-linkfr307-m2_firmwareup to 1.2.5
tp-linkfr307-m2_firmware1.2.5
tp-linkfr205_firmwareup to 1.0.3
tp-linkfr205_firmware1.0.3
tp-linkfr365_firmwareup to 1.1.10
tp-linkfr365_firmware1.1.10
tp-linkg611_firmwareup to 1.2.2
tp-linkg611_firmware1.2.2
tp-linkg36_firmwareup to 1.1.4
tp-linkg36_firmware1.1.4

References

Back to CVE Database