Critical CVSS: 9.3 CVE-2025-7850 A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
Critical CVSS: 9.3 CVE-2025-6542 An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.