An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 21 Oct 2025 00:45:00 +0000

Type Values Removed Values Added
Description An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
Title OS command injection using information obtained from the web management interface
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2025-10-21T00:21:42.535Z

Reserved: 2025-06-23T17:48:07.425Z

Link: CVE-2025-6541

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-21T01:15:36.103

Modified: 2025-10-21T01:15:36.103

Link: CVE-2025-6541

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.