PT-2026-67451 · Tp Link · Omada
CVE-2025-9291
·
Published
2026-08-03
·
Updated
2026-08-05
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Omada devices (affected versions not specified)
Description
A certification validation weakness exists in the communication between affected devices and cloud controllers. The certificate identity verification process fails to adequately validate that a presented certificate corresponds to the expected cloud controller hostname. This flaw may allow certificate validation protections to be bypassed under specific conditions, potentially enabling the interception or modification of communication between the devices and cloud controllers.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Omada