• News/
  • https://www.bleepingcomputer.com/news/security/tp-link-warns-of-critical-command-injection-flaw-in-omada-gateways/

TP-Link warns of critical command injection flaw in Omada gateways

BleepingComputer
·
Bill Toulas
·
Published Oct 21, 2025
·
Updated

TP-Link is warning of two command injection vulnerabilities in Omada gateway devices that could be exploited to execute arbitrary OS commands. Omada gateways are marketed as full-stack solutions (router, firewall, VPN gateway) for small to medium businesses, and are constantly increasing in popularity. Although the two security issues lead to the same result when triggered, only one of them, identified as CVE-2025-6542 with a critical severity rating of 9.3, can be exploited by a remote attacker without authentication. The second flaw is tracked as CVE-2025-6541 and received a lower severity score of 8.6. However, it can be exploited only if the attacker can log into the web management interface. “An arbitrary OS command may be executed on Omada gateways by the user who can log in to the web management interface or by a remote unauthenticated attacker,” reads TP-Link's advisory. “Attackers may execute arbitrary commands on the device’s underlying operating system,” the company adds. The risk the two vulnerabilities poses is significant as it can lead to a full compromise, data theft, lateral movement, and persistence. CVE-2025-6541 and CVE-2025-6542 impact 13 Omada gateway models in the firmware versions listed below: Affected Product Model Affected Version Fixed Version ER8411 < 1.3.3 Build 20251013 Rel.44647 >= 1.3.3 Build 20251013 Rel.44647 ER7412-M2 < 1.1.0 Build 20251015 Rel.63594 >= 1.1.0 Build 20251015 Rel.63594 ER707-M2 < 1.3.1 Build 20251009 Rel.67687 >= 1.3.1 Build...

Read full article

Affected Software

1 affected component
TP-Link Omada gateway
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical command injection vulnerability found in TP-Link's Omada gateway devices.

2

What security implications are discussed?

The vulnerabilities could allow attackers to execute arbitrary operating system commands on affected devices.

3

What products or software are affected?

The affected products are TP-Link Omada gateways, which serve as routers, firewalls, and VPN gateways.

4

Who is the target audience for the TP-Link Omada gateways?

The Omada gateways are primarily marketed towards small to medium businesses.

5

When was this security vulnerability published?

The security vulnerability was reported on October 21, 2025.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203