Unrated severityNVD Advisory· Published Jan 26, 2026· Updated Feb 3, 2026
Blind Server-Side Request Forgery (SSRF) in Omada Controller
CVE-2025-9522
Description
Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information.
Affected products
1- TP-Link Systems Inc./Omada Controllerv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- https//support.omadanetworks.com/us/download/software/omada-controller/mitrepatch
- support.omadanetworks.com/us/document/115200/mitrevendor-advisory
News mentions
0No linked articles in our index yet.