H-ISAC TLP White Vulnerability Bulletin TP-Link Security Advisory Released (CVE-2025-7850 and CVE-2025-7851)

On October 21, 2025, TP-Link released a security advisory concerning its Omada gateway devices to address two severe vulnerabilities, tracked as CVE-2025-7850 and CVE-2025-7851.

The first flaw allows command execution, while the second provides root shell access, posing an extreme risk of full network compromise. Immediate firmware updates are strongly recommended for all affected models to prevent full device compromise.

Health-ISAC is sharing this to increase situational awareness and encourage organizations to assess their level of risk to these vulnerabilities.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272