A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker could execute arbitrary JavaScript in the administrator’s browser, potentially exposing sensitive information and compromising confidentiality.
Metrics
Affected Vendors & Products
References
History
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link omada Controller Tp-link omada Software Controller |
|
| Vendors & Products |
Tp-link
Tp-link omada Controller Tp-link omada Software Controller |
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker could execute arbitrary JavaScript in the administrator’s browser, potentially exposing sensitive information and compromising confidentiality. | |
| Title | Cross-Site Scripting (XSS) on Omada Controllers | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published: 2026-01-22T21:48:35.662Z
Updated: 2026-01-22T21:55:10.732Z
Reserved: 2025-08-20T22:24:18.301Z
Link: CVE-2025-9289
No data.
Status : Received
Published: 2026-01-22T22:16:15.787
Modified: 2026-01-22T22:16:15.787
Link: CVE-2025-9289
No data.