PatchSiren cyber security CVE debrief
CVE-2025-9290 TP-Link Systems Inc. CVE debrief
An authentication weakness was identified in Omada Controllers, Gateways and Access Points due to improper handling of random values. This CVE record describes a medium-severity vulnerability with a CVSS score of 6. The vulnerability allows an attacker with advanced network positioning to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.
- Vendor
- TP-Link Systems Inc.
- Product
- Omada Software Controller
- CVSS
- MEDIUM 6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-23
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-01-23
- Advisory updated
- 2026-10-07
Who should care
Network administrators and security teams responsible for Omada Controllers, Gateways and Access Points should assess exposure and prioritize remediation. This includes operators managing these systems, platform administrators, vulnerability management teams, and security teams that oversee the protection of sensitive information and confidentiality. They should verify and upgrade vulnerable versions, review network positioning and segmentation controls,
Why it matters
CVE-2025-9290 is a medium-severity authentication weakness in Omada Controllers, Gateways and Access Points. Defenders should prioritize verifying and upgrading vulnerable versions, reviewing network positioning and segmentation controls, and implementing additional monitoring and logging to detect potential exploitation attempts.
- Verify and upgrade vulnerable versions to prevent potential exposure of sensitive information
- Review network positioning and segmentation controls to prevent unauthorized access
- Implement additional monitoring and logging to detect potential exploitation attempts
- Assess and update incident response plans to address potential confidentiality impacts
Technical summary
The vulnerability is caused by improper handling of random values in Omada Controllers, Gateways and Access Points, allowing an attacker to intercept adoption traffic and forge valid authentication through offline precomputation. The affected products include Omada Controller, OC200, OC220, OC300, OC400, ER605, ER7206, ER7406, ER707-M2, ER7412-M2, ER8411, ER706W, EAP655-Wall, EAP660 HD, EAP620 HD, EAP610-Outdoor, EAP610, EAP623-Outdoor HD, EAP625-Outdoor HD, EAP772, EAP772-Outdoor, EAP770, EAP723, EAP773, EAP783, EAP787, EAP720, EAP725-Wall, EAP215 Bridge Kit, EAP211 Bridge Kit, Beam Bridge 5 UR, EAP603GP-Desktop, EAP615GP-Wall, EAP625GP-Wall, EAP610GP-Desktop, EAP650GP-Desktop, EAP653, EAP650-Outdoor, EAP230-Wall, EAP235-Wall, EAP603-Outdoor, EAP653 UR, EAP650-Desktop, EAP615-Wall, EAP100-Bridge Kit, ER706W-4G, DR3220V-4G, DR3650V-4G, DR3650V, ER701-5G-Outdoor, ER605W, ER7212PC, FR365, G36W-4G, EAP653 UR
Defensive priority
Defenders should prioritize verifying and upgrading vulnerable Omada Controller, Gateway, and Access Point versions according to vendor advisories.
Recommended defensive actions
- Verify and upgrade vulnerable Omada Controller versions according to vendor advisories.
- Verify and upgrade vulnerable Omada Gateway versions according to vendor advisories.
- Verify and upgrade vulnerable Omada Access Point versions according to vendor advisories.
- Review network positioning and segmentation controls to prevent unauthorized access.
- Implement additional monitoring and logging to detect potential exploitation attempts.
- Assess and update incident response plans to address potential confidentiality impacts.
- Conduct a thorough review of network configurations to ensure proper isolation of affected devices.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected products. However, specific version details and remediation steps require verification from official vendor sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-9290 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-9290
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-9290 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-9290
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://support.omadanetworks.com/en/download/
f23511db-6c3e-4e32-a477-6aa17d310630 - Product
-
Source reference
Unverified legacy reference
URL: https://support.omadanetworks.com/us/document/114950/
f23511db-6c3e-4e32-a477-6aa17d310630 - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://support.omadanetworks.com/us/download/
f23511db-6c3e-4e32-a477-6aa17d310630 - Product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.