TROYANOSYVIRUS
Voltar para CVEs

CVE-2025-9520

MEDIUM
6.8

Descricao

An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.

Detalhes CVE

Pontuacao CVSS v3.16.8
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosHIGH
Interacao do usuarioREQUIRED
Publicado1/26/2026
Ultima modificacao3/11/2026
Fontenvd
Avistamentos honeypot0

Produtos afetados

tp-link:omada_controller

Fraquezas (CWE)

CWE-639

Referencias

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.