跳到主要内容
CodeAuditAgent

CVE-2025-9291

A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.

弱点类型

A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.

受影响产品

  • tp-link omada_fusion_2.5g_firmware
  • tp-link omada_fusion_2.5g
  • tp-link omada_er707-m2_firmware
  • tp-link omada_er707-m2
  • tp-link omada_er7206_firmware
  • tp-link omada_er7206
  • tp-link omada_er706w_firmware
  • tp-link omada_er706w

参考链接

赶在攻击者之前发现漏洞。

使用 GitHub 登录,一分钟内即可运行你的第一次审计。免费版无需信用卡。