CVE-2025-6542: OS command injection in multiple parameters
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6542?
CVE-2025-6542 has a high severity due to the potential for arbitrary OS command execution by a remote unauthenticated attacker.
How do I fix CVE-2025-6542?
To remediate CVE-2025-6542, update the affected TP-Link firmware to the latest version that addresses this vulnerability.
Which TP-Link products are affected by CVE-2025-6542?
CVE-2025-6542 affects multiple TP-Link firmware versions, including those for the ER8411, ER7412-m2, ER707-m2, ER7206, ER605, ER706w, ER706w-4g, ER7212pc, G36, G611, FR365, FR205, and FR307-m2.
What type of attack can exploit CVE-2025-6542?
CVE-2025-6542 can be exploited through remote command execution, allowing attackers to execute arbitrary operating system commands.
Is user authentication required to exploit CVE-2025-6542?
No, CVE-2025-6542 can be exploited by remote attackers without any form of authentication.