{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T03:46:50.608","vulnerabilities":[{"cve":{"id":"CVE-2025-9289","sourceIdentifier":"f23511db-6c3e-4e32-a477-6aa17d310630","published":"2026-01-22T22:16:15.787","lastModified":"2026-06-17T10:08:40.947","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker could execute arbitrary JavaScript in the administrator’s browser, potentially exposing sensitive information and compromising confidentiality."},{"lang":"es","value":"Una vulnerabilidad de cross-site scripting (XSS) fue identificada en un parámetro en los Controladores Omada debido a una sanitización de entrada inadecuada. La explotación requiere condiciones avanzadas, como el posicionamiento en la red o la emulación de una entidad de confianza, y la interacción del usuario por parte de un administrador autenticado. Si tiene éxito, un atacante podría ejecutar JavaScript arbitrario en el navegador del administrador, exponiendo potencialmente información sensible y comprometiendo la confidencialidad."}],"affected":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","affectedData":[{"vendor":"TP-Link Systems Inc.","product":"Omada Software Controller","defaultStatus":"unaffected","platforms":["Windows","Linux"],"versions":[{"version":"0","lessThan":"6.0.0.24","versionType":"custom","status":"affected"}]},{"vendor":"TP-Link Systems Inc.","product":"Omada OC200, OC220, OC300, OC400","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.0.0.34","versionType":"custom","status":"affected"}]},{"vendor":"TP-Link Systems Inc.","product":"Omada cloud controller","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.0.0.100","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-23T20:15:52.769770Z","id":"CVE-2025-9289","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tp-link:omada_controller:*:*:*:*:-:*:*:*","versionEndExcluding":"6.0.0.24","matchCriteriaId":"3B623F6F-B033-44B4-9F50-97CE3C0F84E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:tp-link:omada_controller:*:*:*:*:cloud:*:*:*","versionEndExcluding":"6.0.0.100","matchCriteriaId":"DB01AAAF-90A1-4DA2-8810-D5A02D11ABCC"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:oc200_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.37.9","matchCriteriaId":"036DEE09-EB29-4F38-A472-181FE88A1EAC"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:oc200:1:*:*:*:*:*:*:*","matchCriteriaId":"D994D0D1-FE36-4CB9-A641-CAAC8D643783"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:oc220_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.2.9","matchCriteriaId":"1836F980-6E1F-4305-973E-AB34BD046CFD"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:oc220:1:*:*:*:*:*:*:*","matchCriteriaId":"077DD2BF-32E3-434E-B040-9B4C48F419CA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:oc300_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.31.9","matchCriteriaId":"1188840C-7B7B-4D07-A4D4-DED7D02E2971"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:oc300:1.6:*:*:*:*:*:*:*","matchCriteriaId":"8E90417C-17A3-4D55-9764-4EF93D19B610"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:oc400_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.9.9","matchCriteriaId":"5B04AEC9-E614-4C99-98B5-568D845C3153"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:oc400:1.6:*:*:*:*:*:*:*","matchCriteriaId":"15655343-B8B7-4C17-8F9B-E90823407861"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:oc200_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.22.9","matchCriteriaId":"4F791A1D-CF64-44C9-B17C-FF8632E3B6BF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:oc200:2:*:*:*:*:*:*:*","matchCriteriaId":"86D6AE05-E5BE-41A6-B3ED-16C5B15BF2A2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tp-link:omada_controller:*:*:*:*:-:*:*:*","versionEndExcluding":"6.0.0.34","matchCriteriaId":"64544C00-6B20-4320-850B-B83F99D72BC6"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:oc200:1:*:*:*:*:*:*:*","matchCriteriaId":"D994D0D1-FE36-4CB9-A641-CAAC8D643783"},{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:oc200:2:*:*:*:*:*:*:*","matchCriteriaId":"86D6AE05-E5BE-41A6-B3ED-16C5B15BF2A2"},{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:oc220:1:*:*:*:*:*:*:*","matchCriteriaId":"077DD2BF-32E3-434E-B040-9B4C48F419CA"},{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:oc300:1.6:*:*:*:*:*:*:*","matchCriteriaId":"8E90417C-17A3-4D55-9764-4EF93D19B610"},{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:oc400:1.6:*:*:*:*:*:*:*","matchCriteriaId":"15655343-B8B7-4C17-8F9B-E90823407861"}]}]}],"references":[{"url":"https://support.omadanetworks.com/us/document/114950/","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Vendor Advisory"]},{"url":"https://support.omadanetworks.com/us/download/","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Product"]}]}}]}