TP-Link routers struck again as new vulnerabilities exposed deep firmware cracks, leading to full remote device control


  • CVE-2025-7851 comes from residual debug code left in patched firmware
  • CVE-2025-7850 allows command injection via the WireGuard VPN interface
  • Exploiting one vulnerability made the other easier to successfully trigger

Two recently revealed flaws in TP-Link’s Omada and Festa VPN routers have revealed deep weaknesses in the company’s firmware security.

The vulnerabilities, identified as CVE-2025-7850 and CVE-2025-7851, were identified by researchers at Forescout’s Vedere Labs.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top