Er706w
Vulnerabilities
5
Known exploited
0
Max CVSS
9.3
Top EPSS
0.02171
Severity breakdown
Critical
2
High
2
Medium
1
Low
0
Also matched as (raw): er706w_firmware
Top vulnerabilities
CVE-2025-7850A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
CVE-2025-6542An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
CVE-2025-7851An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
CVE-2025-6541An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
CVE-2025-9290An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.