CVE-2025-9291
—CVSS 4.0
7.7 high
EPSS
<1%p3
Published
()
Modified
Description
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.
- Vendors
- tp-link
- Products
- omada fusion 2.5g firmware, omada er707-m2 firmware, omada er7206 firmware, omada er706w firmware, omada er8411 firmware, omada er605 firmware, omada er7412-m2 firmware, omada er706w-4g firmware, omada er703wp-4g-outdoor firmware, omada er706wp-4g firmware, omada s7500-24y4c firmware, omada s7500-26xf6y firmware
- Weakness
- CWE-295
- Vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.