CVE-2025-9290Medium· 5.9▾ SunlitAn authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker t…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.
omada_controller < 6.0.0.24omada_controller < 6.0.0.100oc200_firmware < 1.37.9oc220_firmware < 1.1.3oc300_firmware < 1.31.9oc400_firmware < 1.9.9oc200_firmware < 2.22.9oc220_firmwareer605_firmware < 2.3.2er7206_firmware < 2.2.2er7406_firmware < 1.2.2er707-m2_firmware < 1.3.1er7412-m2_firmware < 1.1.0er8411_firmware < 1.3.5er706w_firmware < 1.2.1er706w-4g_firmware < 1.2.1er706wp-4g_firmware < 1.1.0er703wp-4g-outdoor_firmware < 1.1.0dr3220v-4g_firmware < 1.1.0dr3650v-4g_firmware < 1.1.0dr3650v_firmware < 1.1.0er701-5g-outdoor_firmware < 1.0.0er605w_firmware < 2.0.2er7212pc_firmware < 2.2.1fr365_firmware < 1.1.10g36w-4g_firmware < 1.1.5eap655-wall_firmware < 1.6.2eap660_hd_firmware < 1.6.1eap620_hd_firmware < 1.6.1eap610-outdoor_firmware < 1.6.1eap610_firmware < 1.6.1eap623-outdoor_hd_firmware < 1.6.1eap625-outdoor_hd_firmware < 1.6.1eap772_firmware < 1.3.2eap772-outdoor_firmware < 1.3.2eap770_firmware < 1.3.2eap723_firmware < 1.3.2eap773_firmware < 1.1.2eap783_firmware < 1.1.2eap772_firmware < 1.1.2eap787_firmware < 1.1.2eap720_firmware < 1.1.2eap723_firmware < 1.1.2eap725-wall_firmware < 1.1.2eap215_bridge_kit_firmware < 1.1.4eap211_bridge_kit_firmware < 1.1.4beam_bridge_5_ur_firmware < 1.1.5eap603gp-desktop_firmware < 1.1.0eap615gp-wall_firmware < 1.1.0eap625gp-wall_firmware < 1.1.0eap610gp-desktop_firmware < 1.1.0eap650gp-desktop_firmware < 1.0.1eap653_firmware < 1.3.3eap650-outdoor_firmware < 1.3.3eap230-wall_firmware < 3.3.1eap235-wall_firmware < 3.3.1eap603-outdoor_firmware < 1.5.1eap653_ur_firmware < 1.4.2eap650-desktop_firmware < 1.1.0eap615-wall_firmware < 1.1.0eap100-bridge_kit_firmware < 1.0.3er706w-4g_firmware < 2.1.0omada_controller < 6.0.0.34omada_controller < 5.15.24Upgrade past the affected range:
omada_controller 5.15.24oc200_firmware 2.22.9oc220_firmware 1.1.3oc300_firmware 1.31.9oc400_firmware 1.9.9er605_firmware 2.3.2er7206_firmware 2.2.2er7406_firmware 1.2.2er707-m2_firmware 1.3.1er7412-m2_firmware 1.1.0er8411_firmware 1.3.5er706w_firmware 1.2.1er706w-4g_firmware 2.1.0er706wp-4g_firmware 1.1.0er703wp-4g-outdoor_firmware 1.1.0dr3220v-4g_firmware 1.1.0dr3650v-4g_firmware 1.1.0dr3650v_firmware 1.1.0er701-5g-outdoor_firmware 1.0.0er605w_firmware 2.0.2er7212pc_firmware 2.2.1fr365_firmware 1.1.10g36w-4g_firmware 1.1.5eap655-wall_firmware 1.6.2eap660_hd_firmware 1.6.1eap620_hd_firmware 1.6.1eap610-outdoor_firmware 1.6.1eap610_firmware 1.6.1eap623-outdoor_hd_firmware 1.6.1eap625-outdoor_hd_firmware 1.6.1eap772_firmware 1.1.2eap772-outdoor_firmware 1.3.2eap770_firmware 1.3.2eap723_firmware 1.1.2eap773_firmware 1.1.2eap783_firmware 1.1.2eap787_firmware 1.1.2eap720_firmware 1.1.2eap725-wall_firmware 1.1.2eap215_bridge_kit_firmware 1.1.4eap211_bridge_kit_firmware 1.1.4beam_bridge_5_ur_firmware 1.1.5eap603gp-desktop_firmware 1.1.0eap615gp-wall_firmware 1.1.0eap625gp-wall_firmware 1.1.0eap610gp-desktop_firmware 1.1.0eap650gp-desktop_firmware 1.0.1eap653_firmware 1.3.3eap650-outdoor_firmware 1.3.3eap230-wall_firmware 3.3.1eap235-wall_firmware 3.3.1eap603-outdoor_firmware 1.5.1eap653_ur_firmware 1.4.2eap650-desktop_firmware 1.1.0eap615-wall_firmware 1.1.0eap100-bridge_kit_firmware 1.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2018-25321Medium· 4.3TP-Link TL-WR720N CSRF via Administrative Interfaces (firmware V1_130719)
CVE-2025-62673High· 8.0Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containin…
CVE-2026-22223High· 8.0An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrati…
CVE-2026-22221High· 8.0An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrativ…
CVE-2026-15141Medium· 5.7The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficie…
CVE-2025-14300High· 8.1The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication