CVE-2025-9289 - CVE House
Back to Database
Status published Medium CVE-2025-9289

Cross-Site Scripting (XSS) on Omada Controllers

Vulnerability Description

A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker could execute arbitrary JavaScript in the administrator’s browser, potentially exposing sensitive information and compromising confidentiality.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9289

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Francesco La Spina, Stanislav Dashevskyi from Forescout Technologies

Affected Vendor

TP-Link Systems Inc.

View all reports →

Affected Software

Omada Software Controller, Omada OC200, OC220, OC300, OC400, Omada cloud controller
Vulnerable Versions:
0

Timeline

Official Publish: January 22nd, 2026
Last Modified: January 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)