TP-Link routers hit again as new vulnerabilities reveal deep firmware cracks, leading to full remote control of device


  • CVE-2025-7851 stems from residual debugging code left in patched firmware
  • CVE-2025-7850 enables command injection through the WireGuard VPN interface
  • Exploitation of one vulnerability made the other easier to successfully trigger

Two recently disclosed flaws in TP-Link’s Omada and Festa VPN routers have revealed deep-seated weaknesses in the company’s firmware security.

The vulnerabilities, tracked as CVE-2025-7850 and CVE-2025-7851, were identified by researchers from Forescout’s Vedere Labs.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top