MEDIUM · 6.5

CVE-2025-9291

A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certif...

Vulnerability Description

A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
Tp-LinkOmada Fusion 2.5G Firmware-
Tp-LinkOmada Fusion 2.5G-
Tp-LinkOmada Er707-M2 Firmware-
Tp-LinkOmada Er707-M2-
Tp-LinkOmada Er7206 Firmware-
Tp-LinkOmada Er7206-
Tp-LinkOmada Er706W Firmware-
Tp-LinkOmada Er706W-
Tp-LinkOmada Er8411 Firmware-
Tp-LinkOmada Er8411-
Tp-LinkOmada Er605 Firmware-
Tp-LinkOmada Er605-
Tp-LinkOmada Er7412-M2 Firmware-
Tp-LinkOmada Er7412-M2-
Tp-LinkOmada Er706W-4G Firmware-
Tp-LinkOmada Er706W-4G-
Tp-LinkOmada Er703Wp-4G-Outdoor Firmware-
Tp-LinkOmada Er703Wp-4G-Outdoor-
Tp-LinkOmada Er706Wp-4G Firmware-
Tp-LinkOmada Er706Wp-4G-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-9291?

CVE-2025-9291 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certif...

How severe is CVE-2025-9291?

CVE-2025-9291 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-9291?

Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Omada Fusion 2.5G Firmware, Tp-Link Omada Fusion 2.5G, Tp-Link Omada Er707-M2 Firmware, Tp-Link Omada Er707-M2, Tp-Link Omada Er7206 Firmware.