Cross-Site Scripting Vulnerability in Omada Controllers by Omada Networks
CVE-2025-9289
Key Information:
- Vendor
Tp-link Systems Inc.
- Vendor
- CVE Published:
- 22 January 2026
What is CVE-2025-9289?
A Cross-Site Scripting (XSS) vulnerability was detected in Omada Controllers, primarily stemming from inadequate input sanitization. This flaw may allow attackers to inject arbitrary JavaScript if certain conditions, such as network position or mimicking a trusted entity, are met alongside administrator interaction. Successful exploitation could lead to unauthorized access to sensitive information via an authenticated administrator's browser, posing a significant threat to data confidentiality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Omada cloud controller 0 < 6.0.0.100
Omada OC200, OC220, OC300, OC400 0 < 6.0.0.34
Omada Software Controller Windows 0 < 6.0.0.24
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
