CVE-2025-9289 Details
Description
A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker could execute arbitrary JavaScript in the administrator’s browser, potentially exposing sensitive information and compromising confidentiality.
A Cross-Site Scripting (XSS) vulnerability has been identified in Omada Controllers, including software versions for Windows and Linux, as well as cloud and certain hardware controllers. This vulnerability arises from improper input sanitization, allowing an authenticated administrator to execute arbitrary JavaScript in their browser. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity.
Users are advised to update to the latest firmware version available on the Omada Download Center. After the firmware upgrade, changing the password is recommended to mitigate the risk of password leakage.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.omadanetworks.com/us/document/114950/ | TPLink | Vendor Advisory |
| https://support.omadanetworks.com/us/download/ | TPLink | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link omada controller | < 6.0.0.24 < 6.0.0.100 < 6.0.0.34 |
CPE
Remediation
| |
| tp-link oc200 firmware | < 1.37.9 < 2.22.9 |
CPE
Remediation
| |
| tp-link oc200 | 1 2 |
CPE
Remediation
| |
| tp-link oc220 firmware | < 1.2.9 |
CPE
Remediation
| |
| tp-link oc220 | 1 |
CPE
Remediation
| |
| tp-link oc300 firmware | < 1.31.9 |
CPE
Remediation
| |
| tp-link oc300 | 1.6 |
CPE
Remediation
| |
| tp-link oc400 firmware | < 1.9.9 |
CPE
Remediation
| |
| tp-link oc400 | 1.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 16, 2026 | Initial Analysis | [email protected] |
| Jan 22, 2026 | New CVE Received | TPLink |