Unrated severityNVD Advisory· Published Jan 26, 2026· Updated Jan 26, 2026
IDOR Leading to Owner Account Hijacking in Omada Controller
CVE-2025-9520
Description
An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.
Affected products
1- TP-Link Systems Inc./Omada Controllerv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- support.omadanetworks.com/us/download/software/omada-controller/mitrepatch
- support.omadanetworks.com/us/document/115200/mitrevendor-advisory
News mentions
0No linked articles in our index yet.