CVE-2025-9290
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6
- CVSS vector
- CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.21%
- CWE
- CWE-760
- Published
- 2026-01-22
- Last modified
- 2026-03-12
Affected products
- TP-Link Systems Inc. Omada Software Controller
- TP-Link Systems Inc. Omada Cloud Controller
- TP-Link Systems Inc. Omada Hardware Controller (OC200, OC300, OC400)
- TP-Link Systems Inc. Omada Hardware Controller OC220
- TP-Link Systems Inc. Omada Gateway (ER605 v2.0)
- TP-Link Systems Inc. Omada Gateway (ER7206 v2.0)
- TP-Link Systems Inc. Omada Gateway (ER7406, ER706W, ER706-4G)
- TP-Link Systems Inc. Omada Gateway (ER707-M2, ER-8411)
Weakness type
Related vulnerabilities
- CVE-2026-46749 — A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected...
- CVE-2026-9370 — ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
- CVE-2024-13951 — One way hash with predictable salt
- CVE-2025-26486 — Broken or Risky Cryptographic Algorithm, Use of Password Hash...
- CVE-2023-22599
- CVE-2021-38314 — Gutenberg Template Library & Redux Framework <= 4.2.11 Sensitive Information Disclosure
- CVE-2020-28214 — A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all...
- CVE-2018-5552 — DocuTrac DTISQLInstaller.exe Hard-Coded Salt