Search
Search Results (5 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-9290 | 1 Tp-link | 4 Omada Access Point, Omada Controller, Omada Gateway and 1 more | 2026-01-23 | N/A |
| An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality. | ||||
| CVE-2025-7851 | 1 Tp-link | 27 Er605, Er605 Firmware, Er706w and 24 more | 2025-10-24 | 9.8 Critical |
| An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. | ||||
| CVE-2025-7850 | 1 Tp-link | 27 Er605, Er605 Firmware, Er706w and 24 more | 2025-10-24 | 7.2 High |
| A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. | ||||
| CVE-2025-6542 | 1 Tp-link | 28 Er605, Er605 Firmware, Er706w and 25 more | 2025-10-24 | 9.8 Critical |
| An arbitrary OS command may be executed on the product by a remote unauthenticated attacker. | ||||
| CVE-2025-6541 | 1 Tp-link | 28 Er605, Er605 Firmware, Er706w and 25 more | 2025-10-24 | 8.8 High |
| An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. | ||||
Page 1 of 1.