CVE-2025-9291
Severity CVSS v4.0:
HIGH
Type:
CWE-295
Improper Certificate Validation
Publication date:
03/08/2026
Last modified:
03/08/2026
Description
A<br />
certification validation weakness exists in communication between affected<br />
Omada devices and cloud controllers. Certificate identity verification does not<br />
adequately validate that a presented certificate corresponds to the expected<br />
cloud controller hostname, which may allow certificate validation protections<br />
to be bypassed under specific conditions.<br />
<br />
<br />
<br />
<br />
<br />
Successful<br />
exploitation may allow interception or modification of communication between<br />
affected devices and cloud controllers.
Impact
Base Score 4.0
7.70
Severity 4.0
HIGH



