CVE-2025-7851
- EPSS 0.06%
- Veröffentlicht 21.10.2025 00:29:05
- Zuletzt bearbeitet 24.10.2025 17:15:43
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
CVE-2025-7850
- EPSS 1.36%
- Veröffentlicht 21.10.2025 00:28:11
- Zuletzt bearbeitet 24.10.2025 17:15:43
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
CVE-2025-6542
- EPSS 0.12%
- Veröffentlicht 21.10.2025 00:23:08
- Zuletzt bearbeitet 24.10.2025 13:50:10
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
CVE-2025-6541
- EPSS 0.06%
- Veröffentlicht 21.10.2025 00:21:42
- Zuletzt bearbeitet 24.10.2025 13:45:38
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
CVE-2024-21827
- EPSS 0.15%
- Veröffentlicht 25.06.2024 14:15:10
- Zuletzt bearbeitet 04.11.2025 18:15:50
A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An att...
CVE-2023-47618
- EPSS 0.34%
- Veröffentlicht 06.02.2024 17:15:10
- Zuletzt bearbeitet 04.11.2025 19:16:06
A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An at...
CVE-2023-46683
- EPSS 0.78%
- Veröffentlicht 06.02.2024 17:15:09
- Zuletzt bearbeitet 04.11.2025 19:16:04
A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command i...
CVE-2023-47167
- EPSS 0.78%
- Veröffentlicht 06.02.2024 17:15:09
- Zuletzt bearbeitet 04.11.2025 19:16:05
A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attac...
CVE-2023-47209
- EPSS 0.78%
- Veröffentlicht 06.02.2024 17:15:09
- Zuletzt bearbeitet 04.11.2025 19:16:05
A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An att...
CVE-2023-47617
- EPSS 0.78%
- Veröffentlicht 06.02.2024 17:15:09
- Zuletzt bearbeitet 04.11.2025 19:16:06
A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An...