CVE-2025-9291
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-295
Validación incorrecta de certificados
Fecha de publicación:
03/08/2026
Última modificación:
03/08/2026
Descripción
*** Pendiente de traducción *** A<br />
certification validation weakness exists in communication between affected<br />
Omada devices and cloud controllers. Certificate identity verification does not<br />
adequately validate that a presented certificate corresponds to the expected<br />
cloud controller hostname, which may allow certificate validation protections<br />
to be bypassed under specific conditions.<br />
<br />
<br />
<br />
<br />
<br />
Successful<br />
exploitation may allow interception or modification of communication between<br />
affected devices and cloud controllers.
Impacto
Puntuación base 4.0
7.70
Gravedad 4.0
ALTA



