← Vulnerability feed

Vulnerability record · CVE-2025-7851 · published 21 October 2025

CVE-2025-7851: Tp-link fr307-m2 firmware improper privilege management vulnerability

Tp Link · Fr307 M2 Firmware

An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.

8.7 CVSS 4.0 High EPSS 0.67% · top 49.8% CWE-269 · Improper privilege management
8.7CVSS 4.0 base score
0.67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.

CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-7851 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-19586Tp-link er7212pc firmware os command injection vulnerabilityA pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insuf…EPSS 5.7%9.3CVE-2025-6542Tp-link er8411 firmware os command injection vulnerabilityAn arbitrary OS command may be executed on the product by a remote unauthenticated attacker.EPSS 1.0%9.3CVE-2025-7850Tp-link er8411 firmware os command injection vulnerabilityA command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.EPSS 3.3%8.6CVE-2025-6541Tp-link er706w firmware os command injection vulnerabilityAn arbitrary OS command may be executed on the product by the user who can log in to the web management interface.EPSS 0.68%7.2CVE-2024-21827Tp-link er7206 firmware vulnerabilityA leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.…EPSS 0.87%7.2CVE-2023-47618Tp-link er7206 firmware os command injection vulnerabilityA post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 buil…EPSS 1.9%7.2CVE-2023-46683Tp-link er7206 firmware os command injection vulnerabilityA post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Rou…EPSS 3.4%7.2CVE-2023-47167Tp-link er7206 firmware os command injection vulnerabilityA post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 2…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2025-7851), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.