Vulnerabilities (CVE)

Filtered by vendor Tp-link Subscribe
Filtered by product Er605
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-9290 1 Tp-link 111 Beam Bridge 5 Ur, Beam Bridge 5 Ur Firmware, Dr3220v-4g and 108 more 2026-03-16 N/A 5.9 MEDIUM
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.
CVE-2025-7851 1 Tp-link 26 Er605, Er605 Firmware, Er706w and 23 more 2025-10-24 N/A 9.8 CRITICAL
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
CVE-2025-7850 1 Tp-link 26 Er605, Er605 Firmware, Er706w and 23 more 2025-10-24 N/A 7.2 HIGH
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
CVE-2025-6542 1 Tp-link 26 Er605, Er605 Firmware, Er706w and 23 more 2025-10-24 N/A 9.8 CRITICAL
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
CVE-2025-6541 1 Tp-link 26 Er605, Er605 Firmware, Er706w and 23 more 2025-10-24 N/A 8.8 HIGH
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.