TP-Link is warning of two command injection vulnerabilities in Omada gateway devices that could be exploited to execute arbitrary OS commands. Omada gateways are marketed as full-stack solutions (router, firewall, VPN gateway) for small to medium businesses, and are constantly increasing in popularity. Although the two security issues lead to the same result when triggered, only one of them, identified as CVE-2025-6542 with a critical severity rating of 9.3, can be exploited by a remote attacker without authentication. The second flaw is tracked as CVE-2025-6541 and received a lower severity score of 8.6. However, it can be exploited only if the attacker can log into the web management interface. “An arbitrary OS command may be executed on Omada gateways by the user who can log in to the web management interface or by a remote unauthenticated attacker,” reads TP-Link's advisory. “Attackers may execute arbitrary commands on the device’s underlying operating system,” the company adds. The risk the two vulnerabilities poses is significant as it can lead to a full compromise, data theft, lateral movement, and persistence. CVE-2025-6541 and CVE-2025-6542 impact 13 Omada gateway models in the firmware versions listed below: Affected Product Model Affected Version Fixed Version ER8411 < 1.3.3 Build 20251013 Rel.44647 >= 1.3.3 Build 20251013 Rel.44647 ER7412-M2 < 1.1.0 Build 20251015 Rel.63594 >= 1.1.0 Build 20251015 Rel.63594 ER707-M2 < 1.3.1 Build 20251009 Rel.67687 >= 1.3.1 Build...
TP-Link warns of critical command injection flaw in Omada gateways
BleepingComputer
·Bill Toulas
·Published Oct 21, 2025
·Updated
Affected Software
1 affected component
TP-Link Omada gateway
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical command injection vulnerability found in TP-Link's Omada gateway devices.
2
What security implications are discussed?
The vulnerabilities could allow attackers to execute arbitrary operating system commands on affected devices.
3
What products or software are affected?
The affected products are TP-Link Omada gateways, which serve as routers, firewalls, and VPN gateways.
4
Who is the target audience for the TP-Link Omada gateways?
The Omada gateways are primarily marketed towards small to medium businesses.
5
When was this security vulnerability published?
The security vulnerability was reported on October 21, 2025.