← Vulnerability feed

Vulnerability record · CVE-2025-6541 · published 21 October 2025

CVE-2025-6541: Tp-link er706w firmware os command injection vulnerability

Tp Link · Er706w Firmware

An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.

8.6 CVSS 4.0 High EPSS 0.68% · top 49.6% CWE-78 · OS command injection
8.6CVSS 4.0 base score
0.68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-6541 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-19586Tp-link er7212pc firmware os command injection vulnerabilityA pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insuf…EPSS 5.7%9.3CVE-2025-6542Tp-link er8411 firmware os command injection vulnerabilityAn arbitrary OS command may be executed on the product by a remote unauthenticated attacker.EPSS 1.0%9.3CVE-2025-7850Tp-link er8411 firmware os command injection vulnerabilityA command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.EPSS 3.3%8.7CVE-2025-7851Tp-link fr307-m2 firmware improper privilege management vulnerabilityAn attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.EPSS 0.67%7.2CVE-2024-21827Tp-link er7206 firmware vulnerabilityA leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.…EPSS 0.87%7.2CVE-2023-47618Tp-link er7206 firmware os command injection vulnerabilityA post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 buil…EPSS 1.9%7.2CVE-2023-46683Tp-link er7206 firmware os command injection vulnerabilityA post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Rou…EPSS 3.4%7.2CVE-2023-47167Tp-link er7206 firmware os command injection vulnerabilityA post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 2…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2025-6541), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.