A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker could execute arbitrary JavaScript in the administrator’s browser, potentially exposing sensitive information and compromising confidentiality.
References
| Link | Resource |
|---|---|
| https://support.omadanetworks.com/us/document/114950/ | Vendor Advisory |
| https://support.omadanetworks.com/us/download/ | Product |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
History
16 Mar 2026, 18:06
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Tp-link oc220 Firmware
Tp-link Tp-link oc400 Tp-link oc220 Tp-link omada Controller Tp-link oc200 Firmware Tp-link oc300 Firmware Tp-link oc300 Tp-link oc400 Firmware Tp-link oc200 |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.7 |
| References | () https://support.omadanetworks.com/us/document/114950/ - Vendor Advisory | |
| References | () https://support.omadanetworks.com/us/download/ - Product | |
| Summary |
|
|
| CPE | cpe:2.3:a:tp-link:omada_controller:*:*:*:*:-:*:*:* cpe:2.3:o:tp-link:oc200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:tp-link:oc400_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:tp-link:oc400:1.6:*:*:*:*:*:*:* cpe:2.3:h:tp-link:oc200:2:*:*:*:*:*:*:* cpe:2.3:h:tp-link:oc200:1:*:*:*:*:*:*:* cpe:2.3:o:tp-link:oc300_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:tp-link:oc300:1.6:*:*:*:*:*:*:* cpe:2.3:h:tp-link:oc220:1:*:*:*:*:*:*:* cpe:2.3:a:tp-link:omada_controller:*:*:*:*:cloud:*:*:* cpe:2.3:o:tp-link:oc220_firmware:*:*:*:*:*:*:*:* |
22 Jan 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-22 22:16
Updated : 2026-03-16 18:06
NVD link : CVE-2025-9289
Mitre link : CVE-2025-9289
CVE.ORG link : CVE-2025-9289
JSON object : View
Products Affected
tp-link
- oc300
- oc400
- oc220_firmware
- oc400_firmware
- oc220
- oc200_firmware
- oc300_firmware
- omada_controller
- oc200
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
