CVE-2025-6541

EUVD-2025-35118
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
Affected Products (NVD)
VendorProductVersion
tp-linker706w_firmware
𝑥
< 1.2.1
tp-linker706w_firmware
1.2.1
tp-linker706w-4g_firmware
𝑥
< 1.2.1
tp-linker706w-4g_firmware
1.2.1
tp-linker7212pc_firmware
𝑥
< 2.1.3
tp-linker7212pc_firmware
2.1.3
tp-linkg36_firmware
𝑥
< 1.1.4
tp-linkg36_firmware
1.1.4
tp-linkg611_firmware
𝑥
< 1.2.2
tp-linkg611_firmware
1.2.2
tp-linkfr365_firmware
𝑥
< 1.1.10
tp-linkfr365_firmware
1.1.10
tp-linkfr205_firmware
𝑥
< 1.0.3
tp-linkfr205_firmware
1.0.3
tp-linkfr307-m2_firmware
𝑥
< 1.2.5
tp-linkfr307-m2_firmware
1.2.5
tp-linker8411_firmware
𝑥
< 1.3.3
tp-linker8411_firmware
1.3.3
tp-linker7412-m2_firmware
𝑥
< 1.1.0
tp-linker7412-m2_firmware
1.1.0
tp-linker707-m2_firmware
𝑥
< 1.3.1
tp-linker707-m2_firmware
1.3.1
tp-linker7206_firmware
𝑥
< 2.2.2
tp-linker7206_firmware
2.2.2
tp-linker605_firmware
𝑥
< 2.3.1
tp-linker605_firmware
2.3.1
𝑥
= Vulnerable software versions