CVE-2025-7851
published 2025-10-21CVE-2025-7851: An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.61%
45.0th percentile
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tp-link | er605_firmware | < 2.3.1 | 2.3.1 |
| tp-link | er605_firmware | — | — |
| tp-link | er706w-4g_firmware | < 1.2.1 | 1.2.1 |
| tp-link | er706w-4g_firmware | — | — |
| tp-link | er706w_firmware | < 1.2.1 | 1.2.1 |
| tp-link | er706w_firmware | — | — |
| tp-link | er707-m2_firmware | < 1.3.1 | 1.3.1 |
| tp-link | er707-m2_firmware | — | — |
| tp-link | er7206_firmware | < 2.2.2 | 2.2.2 |
| tp-link | er7206_firmware | — | — |
| tp-link | er7212pc_firmware | < 2.1.3 | 2.1.3 |
| tp-link | er7212pc_firmware | — | — |
| tp-link | er7412-m2_firmware | < 1.1.0 | 1.1.0 |
| tp-link | er7412-m2_firmware | — | — |
| tp-link | er8411_firmware | < 1.3.3 | 1.3.3 |
| tp-link | er8411_firmware | — | — |
| tp-link | fr205_firmware | < 1.0.3 | 1.0.3 |
| tp-link | fr205_firmware | — | — |
| tp-link | fr307-m2_firmware | < 1.2.5 | 1.2.5 |
| tp-link | fr307-m2_firmware | — | — |
| tp-link | fr365_firmware | < 1.1.10 | 1.1.10 |
| tp-link | fr365_firmware | — | — |
| tp-link | g36_firmware | < 1.1.4 | 1.1.4 |
| tp-link | g36_firmware | — | — |
| tp-link | g611_firmware | < 1.2.2 | 1.2.2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
runc-app, runc-stable regression
osv·2025-11-24·CVSS 7.5
CVE-2025-31133 runc-app, runc-stable regression
runc-app, runc-stable regression
USN-7851-1 fixed vulnerabilities in runC. The introduction of a new
upstream release has caused regressions in runc-app and runc-stable.
This update fixes the problem.
Original advisory details:
Lei Wang and Li Fubang discovered that runC incorrectly handled masked
paths. An attacker could possibly replace a container's /dev/null
with a symlink to some other procfs file and possibly escape a container.
(CVE-2025-31133)
Lei Wang and Li Fubang discovered that runC incorrectly handled the
/dev/console bind-mounts. An attacker could potentially exploit this issue
to build-mount a symlink and escape a container. (CVE-2025-52565)
Li Fubang and Tõnis Tiigi discovered that the fix for CVE-2019-16884 was
incomplete. An attacker could possibly use this issue to
GHSA
GHSA-q2rh-fc48-r3gw: An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways
ghsa_unreviewed·2025-10-21
CVE-2025-7851 [HIGH] CWE-269 GHSA-q2rh-fc48-r3gw: An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
No detection rules found.
No public exploits indexed.
https://support.omadanetworks.com/en/document/108456/https://www.forescout.com/blog/new-tp-link-router-vulnerabilities-a-primer-on-rooting-routers/https://www.omadanetworks.com/us/business-networking/all-omada-router/https://www.omadanetworks.com/us/business-networking/omada-pro-router-wired-router/https://www.tp-link.com/us/business-networking/soho-festa-gateway/
2025-10-21
Published