Friday , July 31 2026
5

(CVE-2025-6542, CVSS 9.3)
User Alert: TP-Link warns of critical command injection flaw in Omada gateways

TP-Link Systems has released a firmware update that fixes four serious vulnerabilities in its Omada gateway series, like ER605, ER7206, and ER8411, commonly used in businesses. These flaws—CVE-2025-6541, CVE-2025-6542, CVE-2025-7850, and CVE-2025-7851—can let attackers run arbitrary commands on the devices, sometimes without needing authentication.

According to TP-Link’s advisory, “An arbitrary OS command may be executed on Omada gateways by the user who can log in to the web management interface or by a remote unauthenticated attacker.”

EDIC Propose to invest $2 billion in an AI data center in Bangladesh

Many groups from different countries want to build AI data centers in Bangladesh. Countries like the UK, Japan, and South...
Read More
EDIC Propose to invest $2 billion in an AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

PentesterFlow is a new open-source AI tool for command lines. It is made for penetration testers and bug bounty hunters....
Read More
“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like...
Read More
Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

The two most critical vulnerabilities are:

CVE-2025-6542 (CVSS 9.3 – Critical): Enables remote unauthenticated attackers to execute arbitrary OS commands.

CVE-2025-6541 (CVSS 8.6 – High): Allows authenticated users to execute arbitrary commands through the web management interface.

Both vulnerabilities impact several Omada gateway models, risking full system compromise for network administrators if not fixed. TP-Link warns that “Attackers may execute arbitrary commands on the device’s underlying operating system.”

In addition to the above, TP-Link has disclosed two related command injection issues affecting the same product line:

CVE-2025-7850 (CVSS 9.3): A command injection vulnerability may be exploited after the admin’s authentication on the web portal on Omada gateways.

CVE-2025-7851 (CVSS 8.7): An attacker may obtain the root shell on the underlying with restricted conditions on Omada gateways.

Authenticated users or anyone with compromised admin credentials could gain root access, bypassing all device protections.

The following Omada products are impacted by one or more of the above vulnerabilities:

TP-Link urges all customers to promptly install the latest firmware updates to reduce risks from these vulnerabilities.

Administrators should check device settings and change admin passwords after the update to avoid exploitation from leaked credentials. TP-Link suggests limiting management access to trusted networks and using network segmentation when possible.

cyber security

“InfoSecCon-2025″Draws Hundreds To Dhaka For Cyber Security insights”

Check Also

SolarWinds

SolarWinds Patches 15 Critical Serv-U Flaws

SolarWinds has shared important security updates for its Serv-U file transfer software. These updates fix …