CVE-2025-7375: Unauthenticated Denial-of-Service Vulnerability in Omada EAP610
A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cause the device’s HTTP service to crash. This results in temporary service unavailability until the device is rebooted. This issue affects Omada EAP610 firmware versions prior to 1.6.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7375?
CVE-2025-7375 is classified as a denial-of-service vulnerability that can lead to temporary service unavailability.
How do I fix CVE-2025-7375?
To mitigate CVE-2025-7375, update the Omada EAP610 device to the latest firmware version available.
Who is affected by CVE-2025-7375?
CVE-2025-7375 affects Omada EAP610 devices running versions up to and including 1.6.0.
What kind of attack does CVE-2025-7375 enable?
CVE-2025-7375 enables an attacker with adjacent network access to launch a denial-of-service attack against the device's HTTP service.
Can CVE-2025-7375 be exploited remotely?
No, CVE-2025-7375 requires an attacker to have adjacent network access to exploit the vulnerability.