VYPR

Er7412 M2 Firmware

by TP-Link

CVEs (5)

  • CVE-2025-7851CriOct 21, 2025
    risk 0.64cvss 9.8epss 0.01

    An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.

  • CVE-2025-6542CriOct 21, 2025
    risk 0.64cvss 9.8epss 0.01

    An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.

  • CVE-2025-6541HigOct 21, 2025
    risk 0.57cvss 8.8epss 0.01

    An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.

  • CVE-2025-7850HigOct 21, 2025
    risk 0.47cvss 7.2epss 0.02

    A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.

  • CVE-2025-9290MedJan 23, 2026
    risk 0.38cvss 5.9epss 0.00

    An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge…