
- CVE-2025-7851 stems from residual debug code left in patched firmware
- CVE-2025-7850 enables command injection through the WireGuard VPN interface
- Exploiting one vulnerability made the other easier to trigger successfully
Two newly disclosed flaws in TP-Link’s Omada and Festa VPN routers have exposed deep-seated weaknesses in the company’s firmware security.