Vulnerability Description
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Omada Fusion 2.5G Firmware | - |
| Tp-Link | Omada Fusion 2.5G | - |
| Tp-Link | Omada Er707-M2 Firmware | - |
| Tp-Link | Omada Er707-M2 | - |
| Tp-Link | Omada Er7206 Firmware | - |
| Tp-Link | Omada Er7206 | - |
| Tp-Link | Omada Er706W Firmware | - |
| Tp-Link | Omada Er706W | - |
| Tp-Link | Omada Er8411 Firmware | - |
| Tp-Link | Omada Er8411 | - |
| Tp-Link | Omada Er605 Firmware | - |
| Tp-Link | Omada Er605 | - |
| Tp-Link | Omada Er7412-M2 Firmware | - |
| Tp-Link | Omada Er7412-M2 | - |
| Tp-Link | Omada Er706W-4G Firmware | - |
| Tp-Link | Omada Er706W-4G | - |
| Tp-Link | Omada Er703Wp-4G-Outdoor Firmware | - |
| Tp-Link | Omada Er703Wp-4G-Outdoor | - |
| Tp-Link | Omada Er706Wp-4G Firmware | - |
| Tp-Link | Omada Er706Wp-4G | - |
Related Weaknesses (CWE)
References
- https://support.omadanetworks.com/en/download/firmware/Product
- https://support.omadanetworks.com/us/download/firmware/Product
- https://www.tp-link.com/us/support/faq/5216/Vendor Advisory
FAQ
What is CVE-2025-9291?
CVE-2025-9291 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certif...
How severe is CVE-2025-9291?
CVE-2025-9291 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-9291?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Omada Fusion 2.5G Firmware, Tp-Link Omada Fusion 2.5G, Tp-Link Omada Er707-M2 Firmware, Tp-Link Omada Er707-M2, Tp-Link Omada Er7206 Firmware.