An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
History

Tue, 21 Oct 2025 01:45:00 +0000

Type Values Removed Values Added
Description An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.

Tue, 21 Oct 2025 00:45:00 +0000

Type Values Removed Values Added
Description An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
Title OS command injection in multiple parameters
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2025-10-21T01:16:09.887Z

Reserved: 2025-06-23T17:48:10.419Z

Link: CVE-2025-6542

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-21T01:15:37.063

Modified: 2025-10-21T02:15:35.627

Link: CVE-2025-6542

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.