CVE-2025-7375
CVE-2025-7375 is a medium-severity vulnerability in Tp-link Omada Eap610 Firmware with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v4: 6.9
- EPSS exploit prediction: 0% (13th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-208321
- Weakness: CWE-20
- Affected product: Tp-link Omada Eap610 Firmware
- Published:
- Last modified:
Description
A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cause the device’s HTTP service to crash. This results in temporary service unavailability until the device is rebooted. This issue affects Omada EAP610 firmware versions prior to 1.6.0.
Frequently asked questions
- What is CVE-2025-7375?
- A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cause the device’s HTTP service to crash. This results in temporary service unavailability until the device is rebooted. This issue affects Omada EAP610 firmware versions prior to 1.6.0.
- How severe is CVE-2025-7375?
- CVE-2025-7375 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over an adjacent network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2025-7375 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (13th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-7375?
- CVE-2025-7375 affects Tp-link Omada Eap610 Firmware. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-7375?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-7375 have an EU (EUVD) identifier?
- Yes. CVE-2025-7375 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-208321.
- When was CVE-2025-7375 published?
- CVE-2025-7375 was published on 2026-03-05 and last updated on 2026-06-17.
References
- https://support.omadanetworks.com/en/product/eap610/v3/
- https://support.omadanetworks.com/us/document/118100/
- https://support.omadanetworks.com/us/product/eap610/v3/
Affected products (1)
- cpe:2.3:o:tp-link:omada_eap610_firmware:*:*:*:*:*:*:*:*
More vulnerabilities in Tp-link Omada Eap610 Firmware
- CVE-2025-15629 — High (CVSS 7.5): A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect…
- CVE-2025-15628 — High (CVSS 7.5): Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between…
- CVE-2025-15627 — High (CVSS 7.5): A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys…
- CVE-2025-9291 — Medium (CVSS 6.5): A certification validation weakness exists in communication between affected Omada devices and cloud controllers.…
- CVE-2025-15631 — Medium (CVSS 5.9): A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing…
- CVE-2025-15630 — Medium (CVSS 5.9): A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with…
All CVEs affecting Tp-link Omada Eap610 Firmware →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-93952 — Critical (CVSS 10.0): VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access…
- CVE-2026-77554 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi…
- CVE-2026-77537 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi…
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →