Unrated severityNVD Advisory· Published Oct 21, 2025· Updated Oct 24, 2025
Authenticated OS command execution
CVE-2025-7850
Description
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
Affected products
3- TP-Link Systems Inc./Festa gatewaysv5Range: 0
- TP-Link Systems Inc./Omada gatewaysv5Range: 0
- TP-Link Systems Inc./Omada Pro gatewaysv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- support.omadanetworks.com/en/document/108456/mitrevendor-advisory
- www.omadanetworks.com/us/business-networking/all-omada-router/mitreproduct
- www.omadanetworks.com/us/business-networking/omada-pro-router-wired-router/mitreproduct
- www.tp-link.com/us/business-networking/soho-festa-gateway/mitreproduct
- www.forescout.com/blog/new-tp-link-router-vulnerabilities-a-primer-on-rooting-routers/mitre
News mentions
0No linked articles in our index yet.