CVE-2025-9292 identifies a permissive web security configuration in TP-Link Omada Cloud Controller that could allow cross-origin restrictions to be bypassed. Rated High severity (CVSS 7.5), successful exploitation is complex, requiring an existing client-side injection vulnerability and user access to the affected web interface, which could then lead to unauthorized disclosure of sensitive information. While listed on the Hot List, there is no public exploit code, and its EPSS score indicates a very low likelihood of exploitation. TP-Link has automatically deployed fixes to affected Omada Cloud Controller service versions, requiring no user action.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.13.6CPE matchmatch criteria | cpe:2.3:a:tp-link:aginet:*:*:*:*:*:*:*:* | ||
< 3.9.163CPE matchmatch criteria | cpe:2.3:a:tp-link:deco:*:*:*:*:*:*:*:* | ||
< 1.7.1CPE matchmatch criteria | cpe:2.3:a:tp-link:festa:*:*:*:*:*:*:*:* | ||
< 3.4.350CPE matchmatch criteria | cpe:2.3:a:tp-link:kasa:*:*:*:*:*:*:*:* | ||
< 1.1.21CPE matchmatch criteria | cpe:2.3:a:tp-link:kidshield:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.