← Retour aux CVEs
CVE-2025-9292
HIGH7.5
Description
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow unauthorized disclosure of sensitive information. Fixed in updated Omada Cloud Controller service versions deployed automatically by TP‑Link. No user action is required.
Details CVE
Score CVSS v3.17.5
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie2/13/2026
Derniere modification4/1/2026
Sourcenvd
Observations honeypot0
Produits affectes
tp-link:aginettp-link:decotp-link:festatp-link:kasatp-link:kidshieldtp-link:omadatp-link:omada_guardtp-link:tapotp-link:tethertp-link:tp-partnertp-link:tpcameratp-link:vigitp-link:wi-fi_navitp-link:wifi_toolkit
Faiblesses (CWE)
CWE-942
References
https://www.omadanetworks.com/us/support/faq/4969/(f23511db-6c3e-4e32-a477-6aa17d310630)
https://www.tp-link.com/us/support/faq/4969/(f23511db-6c3e-4e32-a477-6aa17d310630)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.