H-ISAC TLP White Vulnerability Bulletin: TP-Link Security Advisory Released (CVE-2025-6542 and CVE-2025-6541)

On October 21, 2025, TP-Link issued a security advisory regarding multiple firmware versions of its Omada gateway devices to address two high-severity command injection flaws, CVE-2025-6542 and CVE-2025-6541.

The most critical vulnerability, CVE-2025-6542, has a CVSS score of 9.3 and can be exploited by a remote unauthenticated attacker to execute arbitrary OS commands on the underlying system. Immediate firmware updates are strongly recommended for all affected models to prevent full device compromise.

Health-ISAC is sharing this to increase situational awareness and encourage organizations to assess their level of risk to these vulnerabilities.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272