CVE-2025-6541: OS command injection using information obtained from the web management interface
Published Oct 21, 2025
·Updated
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
Affected Software
39 affected components
All of the following
Any of the following
TP-Link Er706w Firmware<1.2.1
TP-Link Er706w Firmware=1.2.1
TP-Link Er706w
All of the following
Any of the following
TP-Link Er706w-4g Firmware<1.2.1
TP-Link Er706w-4g Firmware=1.2.1
TP-Link Er706w-4g
All of the following
Any of the following
TP-Link Er7212pc Firmware<2.1.3
TP-Link Er7212pc Firmware=2.1.3
TP-Link Er7212pc
All of the following
Any of the following
TP-Link G36 Firmware<1.1.4
TP-Link G36 Firmware=1.1.4
TP-Link G36
All of the following
Any of the following
TP-Link G611 Firmware<1.2.2
TP-Link G611 Firmware=1.2.2
TP-Link G611
All of the following
Any of the following
TP-Link Fr365 Firmware<1.1.10
TP-Link Fr365 Firmware=1.1.10
TP-Link Fr365
All of the following
Any of the following
TP-Link Fr205 Firmware<1.0.3
TP-Link Fr205 Firmware=1.0.3
TP-Link Fr205
All of the following
Any of the following
TP-Link Fr307-m2 Firmware<1.2.5
TP-Link Fr307-m2 Firmware=1.2.5
TP-Link Fr307-m2
All of the following
Any of the following
TP-Link Er8411 Firmware<1.3.3
TP-Link Er8411 Firmware=1.3.3
TP-Link Er8411
All of the following
Any of the following
TP-Link Er7412-m2 Firmware<1.1.0
TP-Link Er7412-m2 Firmware=1.1.0
TP-Link Er7412-m2
All of the following
Any of the following
TP-Link Er707-m2 Firmware<1.3.1
TP-Link Er707-m2 Firmware=1.3.1
TP-Link Er707-m2
All of the following
Any of the following
TP-Link Er7206 Firmware<2.2.2
TP-Link Er7206 Firmware=2.2.2
TP-Link ER7206
All of the following
Any of the following
TP-Link Er605 Firmware<2.3.1
TP-Link Er605 Firmware=2.3.1
TP-Link Er605
Event History
Oct 21, 2025
CVE Published
via MITRE·12:21 AM
Data Sourced
via MITRE·12:21 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
News Published
via BleepingComputer·09:11 PM
News Published
via BleepingComputer·09:13 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-6541?
CVE-2025-6541 is classified as critical due to the potential for arbitrary OS command execution.
2
How do I fix CVE-2025-6541?
To mitigate CVE-2025-6541, update the affected TP-Link firmware to the latest version that resolves the vulnerability.
3
Which TP-Link products are affected by CVE-2025-6541?
CVE-2025-6541 affects specific TP-Link routers, including models such as Er706w and Er7212pc with vulnerable firmware versions.
4
Can CVE-2025-6541 lead to unauthorized access?
Yes, CVE-2025-6541 can allow unauthorized users to execute commands on the device, leading to potential system compromise.
5
Is CVE-2025-6541 exploitable remotely?
Yes, CVE-2025-6541 can be exploited remotely by attackers who can access the web management interface.