Cross-Site Scripting Vulnerability in Omada Controllers by Omada Networks
CVE-2025-9289
5.7MEDIUM
Key Information:
- Vendor
Tp-link Systems Inc.
- Vendor
- CVE Published:
- 22 January 2026
What is CVE-2025-9289?
A Cross-Site Scripting (XSS) vulnerability was detected in Omada Controllers, primarily stemming from inadequate input sanitization. This flaw may allow attackers to inject arbitrary JavaScript if certain conditions, such as network position or mimicking a trusted entity, are met alongside administrator interaction. Successful exploitation could lead to unauthorized access to sensitive information via an authenticated administrator's browser, posing a significant threat to data confidentiality.
Affected Version(s)
Omada cloud controller 0 < 6.0.0.100
Omada OC200, OC220, OC300, OC400 0 < 6.0.0.34
Omada Software Controller Windows 0 < 6.0.0.24
References
CVSS V4
Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Francesco La Spina, Stanislav Dashevskyi from Forescout Technologies
