CVE-2025-9291

MEDIUMCVSS 6.5/10EPSS 0.18%

Last modified

CVE-2025-9291 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CVSS 4.0
7.7/10

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.18%

7.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Tp-LinkOmada Fusion 2.5g FirmwareAll versions
Tp-LinkOmada Er707-M2 FirmwareAll versions
Tp-LinkOmada Er7206 FirmwareAll versions
Tp-LinkOmada Er706w FirmwareAll versions
Tp-LinkOmada Er8411 FirmwareAll versions
Tp-LinkOmada Er605 FirmwareAll versions
Tp-LinkOmada Er7412-M2 FirmwareAll versions
Tp-LinkOmada Er706w-4g FirmwareAll versions
Tp-LinkOmada Er703wp-4g-Outdoor FirmwareAll versions
Tp-LinkOmada Er706wp-4g FirmwareAll versions
Tp-LinkOmada S7500-24y4c FirmwareAll versions
Tp-LinkOmada S7500-26xf6y FirmwareAll versions
Tp-LinkOmada S6500-48mpp6y FirmwareAll versions
Tp-LinkOmada S6500-24mpp4y FirmwareAll versions
Tp-LinkOmada S6500-48gp6xf FirmwareAll versions
Tp-LinkOmada S6500-48g6xf FirmwareAll versions
Tp-LinkOmada S6500-24gp4xf FirmwareAll versions
Tp-LinkOmada S6500-24g4xf FirmwareAll versions
Tp-LinkOmada Sx6632yf FirmwareAll versions
Tp-LinkOmada Sx3032f FirmwareAll versions
Tp-LinkOmada Sx3016f FirmwareAll versions
Tp-LinkOmada Sx3008f FirmwareAll versions
Tp-LinkOmada Sg3428xf FirmwareAll versions
Tp-LinkOmada Sx3832mpp FirmwareAll versions
Tp-LinkOmada Sx3832 FirmwareAll versions
Tp-LinkOmada Sx3206hpp FirmwareAll versions
Tp-LinkOmada Sg3428xpp-M2 FirmwareAll versions
Tp-LinkOmada Sg3428x-M2 FirmwareAll versions
Tp-LinkOmada Sg3218xp-M2 FirmwareAll versions
Tp-LinkOmada Sg3210xhp-M2 FirmwareAll versions
Tp-LinkOmada Sg3210x-M2 FirmwareAll versions
Tp-LinkOmada Sg2210xmp-M2 FirmwareAll versions
Tp-LinkOmada Sg6654xhp FirmwareAll versions
Tp-LinkOmada Sg6654x FirmwareAll versions
Tp-LinkOmada Sg6428xhp FirmwareAll versions
Tp-LinkOmada Sg6428x FirmwareAll versions
Tp-LinkOmada Sg5452xmpp FirmwareAll versions
Tp-LinkOmada Sg5452x FirmwareAll versions
Tp-LinkOmada Sg5428xmpp FirmwareAll versions
Tp-LinkOmada Sg5428x FirmwareAll versions
Tp-LinkOmada Sg3452xmpp FirmwareAll versions
Tp-LinkOmada Sg3452xp FirmwareAll versions
Tp-LinkOmada Tl-Sg3452x FirmwareAll versions
Tp-LinkOmada Sg3428xmpp FirmwareAll versions
Tp-LinkOmada Sg3428xmp FirmwareAll versions
Tp-LinkOmada Sg3428x FirmwareAll versions
Tp-LinkOmada Sg2005p-Pd FirmwareAll versions
Tp-LinkOmada Sg3452p FirmwareAll versions
Tp-LinkOmada Sg3452 FirmwareAll versions
Tp-LinkOmada Sg3428mp FirmwareAll versions

Showing 50 of 109 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2025-9291?
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.
How severe is CVE-2025-9291?
CVE-2025-9291 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2025-9291?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-9291?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST