9.8
CVE-2025-7851
- EPSS 0.05%
- Veröffentlicht 21.10.2025 00:29:05
- Zuletzt bearbeitet 24.10.2025 17:15:43
- Quelle f23511db-6c3e-4e32-a477-6aa17d
- CVE-Watchlists
- Unerledigt
Unauthorized root access via debug functionality
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Fr307-m2 Firmware Version < 1.2.5
Tp-link ≫ Fr307-m2 Firmware Version1.2.5 Update-
Tp-link ≫ Fr205 Firmware Version < 1.0.3
Tp-link ≫ Fr205 Firmware Version1.0.3 Update-
Tp-link ≫ Fr365 Firmware Version < 1.1.10
Tp-link ≫ Fr365 Firmware Version1.1.10 Update-
Tp-link ≫ G611 Firmware Version < 1.2.2
Tp-link ≫ G611 Firmware Version1.2.2 Update-
Tp-link ≫ G36 Firmware Version < 1.1.4
Tp-link ≫ G36 Firmware Version1.1.4 Update-
Tp-link ≫ Er7212pc Firmware Version < 2.1.3
Tp-link ≫ Er7212pc Firmware Version2.1.3 Update-
Tp-link ≫ Er706w-4g Firmware Version < 1.2.1
Tp-link ≫ Er706w-4g Firmware Version1.2.1 Update-
Tp-link ≫ Er706w Firmware Version < 1.2.1
Tp-link ≫ Er706w Firmware Version1.2.1 Update-
Tp-link ≫ Er605 Firmware Version < 2.3.1
Tp-link ≫ Er605 Firmware Version2.3.1 Update-
Tp-link ≫ Er7206 Firmware Version < 2.2.2
Tp-link ≫ Er7206 Firmware Version2.2.2 Update-
Tp-link ≫ Er707-m2 Firmware Version < 1.3.1
Tp-link ≫ Er707-m2 Firmware Version1.3.1 Update-
Tp-link ≫ Er7412-m2 Firmware Version < 1.1.0
Tp-link ≫ Er7412-m2 Firmware Version1.1.0 Update-
Tp-link ≫ Er8411 Firmware Version < 1.3.3
Tp-link ≫ Er8411 Firmware Version1.3.3 Update-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.17 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| f23511db-6c3e-4e32-a477-6aa17d310630 | 8.7 | 0 | 0 |
CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.