PT-2026-67451 · Tp Link Systems · Omada Access Point+2

CVE-2025-9291

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions.
Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9291

Affected Products

Omada Access Point
Omada Gateways
Omada Switches