Description

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.

INFO

Published Date :

2026-01-22T23:14:45.823Z

Last Modified :

2026-01-23T20:04:29.976Z

Source :

TPLink
AFFECTED PRODUCTS

The following products are affected by CVE-2025-9290 vulnerability.

Vendors Products
Tp-link
  • Beam Bridge 5 Ur
  • Beam Bridge 5 Ur Firmware
  • Dr3220v-4g
  • Dr3220v-4g Firmware
  • Dr3650v
  • Dr3650v-4g
  • Dr3650v-4g Firmware
  • Dr3650v Firmware
  • Eap100-bridge Kit
  • Eap100-bridge Kit Firmware
  • Eap211 Bridge Kit
  • Eap211 Bridge Kit Firmware
  • Eap215 Bridge Kit
  • Eap215 Bridge Kit Firmware
  • Eap230-wall
  • Eap230-wall Firmware
  • Eap235-wall
  • Eap235-wall Firmware
  • Eap603-outdoor
  • Eap603-outdoor Firmware
  • Eap603gp-desktop
  • Eap603gp-desktop Firmware
  • Eap610
  • Eap610-outdoor
  • Eap610-outdoor Firmware
  • Eap610 Firmware
  • Eap610gp-desktop
  • Eap610gp-desktop Firmware
  • Eap615-wall
  • Eap615-wall Firmware
  • Eap615gp-wall
  • Eap615gp-wall Firmware
  • Eap620 Hd
  • Eap620 Hd Firmware
  • Eap623-outdoor Hd
  • Eap623-outdoor Hd Firmware
  • Eap625-outdoor Hd
  • Eap625-outdoor Hd Firmware
  • Eap625gp-wall
  • Eap625gp-wall Firmware
  • Eap650-desktop
  • Eap650-desktop Firmware
  • Eap650-outdoor
  • Eap650-outdoor Firmware
  • Eap650gp-desktop
  • Eap650gp-desktop Firmware
  • Eap653
  • Eap653 Firmware
  • Eap653 Ur
  • Eap653 Ur Firmware
  • Eap655-wall
  • Eap655-wall Firmware
  • Eap660 Hd
  • Eap660 Hd Firmware
  • Eap720
  • Eap720 Firmware
  • Eap723
  • Eap723 Firmware
  • Eap725-wall
  • Eap725-wall Firmware
  • Eap770
  • Eap770 Firmware
  • Eap772
  • Eap772-outdoor
  • Eap772-outdoor Firmware
  • Eap772 Firmware
  • Eap773
  • Eap773 Firmware
  • Eap783
  • Eap783 Firmware
  • Eap787
  • Eap787 Firmware
  • Er605
  • Er605 Firmware
  • Er605w
  • Er605w Firmware
  • Er701-5g-outdoor
  • Er701-5g-outdoor Firmware
  • Er703wp-4g-outdoor
  • Er703wp-4g-outdoor Firmware
  • Er706w
  • Er706w-4g
  • Er706w-4g Firmware
  • Er706w Firmware
  • Er706wp-4g
  • Er706wp-4g Firmware
  • Er707-m2
  • Er707-m2 Firmware
  • Er7206
  • Er7206 Firmware
  • Er7212pc
  • Er7212pc Firmware
  • Er7406
  • Er7406 Firmware
  • Er7412-m2
  • Er7412-m2 Firmware
  • Er8411
  • Er8411 Firmware
  • Fr365
  • Fr365 Firmware
  • G36w-4g
  • G36w-4g Firmware
  • Oc200
  • Oc200 Firmware
  • Oc220
  • Oc220 Firmware
  • Oc300
  • Oc300 Firmware
  • Oc400
  • Oc400 Firmware
  • Omada Access Point
  • Omada Controller
  • Omada Gateway
  • Omada Software Controller
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-9290.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact