CVE Explorer
CVE-2025-7375
A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cause the device’s HTTP service to crash. This results in temporary service unavailability until the device is rebooted.
This issue affects Omada EAP610 firmware versions prior to 1.6.0.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"EAP610 v3","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.6.0","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f1aaf5b6591bc1c85b289f1535a024b3aa783e3e5ecfddbf9be3d1d24b1e8132 · sha256:b004d4bf44a80db0… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":6.9,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f1aaf5b6591bc1c85b289f1535a024b3aa783e3e5ecfddbf9be3d1d24b1e8132 · sha256:b004d4bf44a80db0… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-20","description":"CWE-20 Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f1aaf5b6591bc1c85b289f1535a024b3aa783e3e5ecfddbf9be3d1d24b1e8132 · sha256:b004d4bf44a80db0… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"tags":["patch"],"url":"https://support.omadanetworks.com/en/product/eap610/v3/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f1aaf5b6591bc1c85b289f1535a024b3aa783e3e5ecfddbf9be3d1d24b1e8132 · sha256:b004d4bf44a80db0… · /containers/cna/references/0
{"tags":["vendor-advisory"],"url":"https://support.omadanetworks.com/us/document/118100/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f1aaf5b6591bc1c85b289f1535a024b3aa783e3e5ecfddbf9be3d1d24b1e8132 · sha256:b004d4bf44a80db0… · /containers/cna/references/2
{"tags":["patch"],"url":"https://support.omadanetworks.com/us/product/eap610/v3/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f1aaf5b6591bc1c85b289f1535a024b3aa783e3e5ecfddbf9be3d1d24b1e8132 · sha256:b004d4bf44a80db0… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.