CVE-2025-9291
Received Received - Intake

Certificate Validation Bypass in Omada Devices

Vulnerability report for CVE-2025-9291, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: TPLink

Description

A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
omada devices *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a certification validation weakness in communication between Omada devices and cloud controllers. The system fails to properly verify that a certificate matches the expected cloud controller hostname, potentially allowing attackers to bypass certificate validation protections.

Impact Analysis

Exploitation may allow attackers to intercept or modify communications between affected devices and cloud controllers. This could lead to unauthorized access, data breaches, or manipulation of device behavior.

Compliance Impact

This vulnerability may allow interception or modification of communication between Omada devices and cloud controllers, potentially exposing sensitive data. This could impact compliance with GDPR by risking unauthorized access to personal data and HIPAA by compromising protected health information during transmission.

Mitigation Strategies

Update Omada devices and cloud controllers to the latest firmware versions to ensure proper certificate validation. Verify that all communication between devices and cloud controllers uses TLS with strict hostname verification. Monitor network traffic for unauthorized interception or modification attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-9291. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart