PT-2026-4304 · Tp Link · Omada Access Point+2
CVE-2025-9290
·
Publicado
2026-01-22
·
Atualizado
2026-03-16
CVSS v4.0
6.0
Média
| Vetor | AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Omada Controllers, Gateways and Access Points (affected versions not specified)
Description
An authentication weakness exists in Omada Controllers, Gateways, and Access Points related to controller-device adoption. This is due to improper handling of random values, allowing an attacker with advanced network positioning to intercept adoption traffic and forge valid authentication through offline precomputation. Successful exploitation could expose sensitive information and compromise confidentiality.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Omada Access Point
Omada Controller
Omada Gateways