PT-2026-4304 · Tp Link · Omada Access Point+2

CVE-2025-9290

·

Publicado

2026-01-22

·

Atualizado

2026-03-16

CVSS v4.0

6.0

Média

VetorAV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Omada Controllers, Gateways and Access Points (affected versions not specified)
Description An authentication weakness exists in Omada Controllers, Gateways, and Access Points related to controller-device adoption. This is due to improper handling of random values, allowing an attacker with advanced network positioning to intercept adoption traffic and forge valid authentication through offline precomputation. Successful exploitation could expose sensitive information and compromise confidentiality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00854
CVE-2025-9290

Produtos afetados

Omada Access Point
Omada Controller
Omada Gateways