CVE-2025-9291
Severity CVSS v4.0:
HIGH
Type:
CWE-295
Improper Certificate Validation
Publication date:
03/08/2026
Last modified:
07/08/2026
Description
A<br />
certification validation weakness exists in communication between affected<br />
Omada devices and cloud controllers. Certificate identity verification does not<br />
adequately validate that a presented certificate corresponds to the expected<br />
cloud controller hostname, which may allow certificate validation protections<br />
to be bypassed under specific conditions.<br />
<br />
<br />
<br />
<br />
<br />
Successful<br />
exploitation may allow interception or modification of communication between<br />
affected devices and cloud controllers.
Impact
Base Score 4.0
7.70
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tp-link:omada_fusion_2.5g_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_fusion_2.5g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er707-m2_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_er707-m2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er7206_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_er7206:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er706w_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_er706w:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er8411_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_er8411:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er605_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_er605:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er7412-m2_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_er7412-m2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er706w-4g_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



