Authentication Weakness on Omada Controllers, Gateways and Access Points
Vulnerability Description
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9290
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies
References
More from TP-Link Systems Inc.
View All →Affected Vendor
TP-Link Systems Inc.
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.