TP-Link routers struck again when new vulnerabilities exposed deep cracks in the firmware, leading to full remote control of the device.




  • CVE-2025-7851 comes from residual debug code left in patched firmware
  • CVE-2025-7850 allows command injection through the WireGuard VPN interface
  • Exploiting one vulnerability made the other easier to trigger successfully

Two recently revealed flaws in TP-Link’s Omada and Festa VPN routers have exposed deep-seated weaknesses in the company’s firmware security.

The vulnerabilities, tracked as CVE-2025-7850 and CVE-2025-7851, were identified by researchers at Forescout’s Vedere Labs.



Leave a Comment

Your email address will not be published. Required fields are marked *