Cross-Site Scripting (XSS) on Omada Controllers
Vulnerability Description
A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker could execute arbitrary JavaScript in the administrator’s browser, potentially exposing sensitive information and compromising confidentiality.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9289
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Francesco La Spina, Stanislav Dashevskyi from Forescout Technologies
References
More from TP-Link Systems Inc.
View All →Affected Vendor
TP-Link Systems Inc.
View all reports →