A
certification validation weakness exists in communication between affected
Omada devices and cloud controllers. Certificate identity verification does not
adequately validate that a presented certificate corresponds to the expected
cloud controller hostname, which may allow certificate validation protections
to be bypassed under specific conditions.





Successful
exploitation may allow interception or modification of communication between
affected devices and cloud controllers.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link omada Access Point
Tp-link omada Gateways
Tp-link omada Switches
Vendors & Products Tp-link
Tp-link omada Access Point
Tp-link omada Gateways
Tp-link omada Switches

Mon, 03 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.
Title Improper Certificate Validation in TP-Link Omada Cloud Communications
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-05T03:57:07.728Z

Reserved: 2025-08-20T22:24:22.941Z

Link: CVE-2025-9291

cve-icon Vulnrichment

Updated: 2026-08-03T18:37:29.109Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T18:16:34.047

Modified: 2026-08-07T15:15:04.800

Link: CVE-2025-9291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:21:52Z

Weaknesses