Unrated severityNVD Advisory· Published Jan 26, 2026· Updated Feb 3, 2026
Password Confirmation Bypass in Omada Controller
CVE-2025-9521
Description
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security.
Affected products
2- TP-Link Systems Inc./Omada Controllerv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- support.omadanetworks.com/us/download/software/omada-controller/mitrepatch
- support.omadanetworks.com/us/document/115200/mitrevendor-advisory
News mentions
0No linked articles in our index yet.