CVE-2025-6542

An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
TPLinkCNA
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
tp-linker8411_firmware
𝑥
< 1.3.3
tp-linker8411_firmware
1.3.3
tp-linker7412-m2_firmware
𝑥
< 1.1.0
tp-linker7412-m2_firmware
1.1.0
tp-linker707-m2_firmware
𝑥
< 1.3.1
tp-linker707-m2_firmware
1.3.1
tp-linker7206_firmware
𝑥
< 2.2.2
tp-linker7206_firmware
2.2.2
tp-linker605_firmware
𝑥
< 2.3.1
tp-linker605_firmware
2.3.1
tp-linker706w_firmware
𝑥
< 1.2.1
tp-linker706w_firmware
1.2.1
tp-linker706w-4g_firmware
𝑥
< 1.2.1
tp-linker706w-4g_firmware
1.2.1
tp-linker7212pc_firmware
𝑥
< 2.1.3
tp-linker7212pc_firmware
2.1.3
tp-linkg36_firmware
𝑥
< 1.1.4
tp-linkg36_firmware
1.1.4
tp-linkg611_firmware
𝑥
< 1.2.2
tp-linkg611_firmware
1.2.2
tp-linkfr365_firmware
𝑥
< 1.1.10
tp-linkfr365_firmware
1.1.10
tp-linkfr205_firmware
𝑥
< 1.0.3
tp-linkfr205_firmware
1.0.3
tp-linkfr307-m2_firmware
𝑥
< 1.2.5
tp-linkfr307-m2_firmware
1.2.5
𝑥
= Vulnerable software versions