CVE-2025-7850
CVE-2025-7850
9.3
CriticalPublished:
Last updated:
Source:f23511db-6c3e-4e32-a477-6aa17d310630
Modified
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Adjacent
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- High
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- Low
- Integrity (Subsequent)
- Low
- Availability (Subsequent)
- High
Description
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
References
f23511db-6c3e-4e32-a477-6aa17d310630
https://support.omadanetworks.com/en/document/108456/f23511db-6c3e-4e32-a477-6aa17d310630
https://www.forescout.com/blog/new-tp-link-router-vulnerabilities-a-primer-on-rooting-routers/f23511db-6c3e-4e32-a477-6aa17d310630
https://www.omadanetworks.com/us/business-networking/all-omada-router/f23511db-6c3e-4e32-a477-6aa17d310630
https://www.omadanetworks.com/us/business-networking/omada-pro-router-wired-router/f23511db-6c3e-4e32-a477-6aa17d310630
https://www.tp-link.com/us/business-networking/soho-festa-gateway/