CVE-2025-9289
Unknown
Unknown - Not Provided
Cross-Site Scripting in Omada Controller Admin Parameter
Publication date: 2026-01-22
Last updated on: 2026-03-16
Assigner: TPLink
Description
Description
A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker could execute arbitrary JavaScript in the administrator’s browser, potentially exposing sensitive information and compromising confidentiality.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tp-link | omada_controller | to 6.0.0.24 (exc) |
| tp-link | omada_controller | to 6.0.0.100 (exc) |
| tp-link | oc200_firmware | to 1.37.9 (exc) |
| tp-link | oc220_firmware | to 1.2.9 (exc) |
| tp-link | oc300_firmware | to 1.31.9 (exc) |
| tp-link | oc400_firmware | to 1.9.9 (exc) |
| tp-link | oc200_firmware | to 2.22.9 (exc) |
| tp-link | omada_controller | to 6.0.0.34 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |