VYPR

Omada Controller

by Omada Networks

CVEs (4)

  • CVE-2025-9292HigFeb 13, 2026
    risk 0.49cvss 7.5epss 0.00

    A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web…

  • CVE-2026-84941MedSep 11, 2026
    risk 0.45cvss epss 0.00

    An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful…

  • CVE-2026-81531MedSep 8, 2026
    risk 0.45cvss epss 0.00

    An information disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users.  Successful…

  • CVE-2025-9522MedJan 26, 2026
    risk 0.34cvss 5.3epss 0.00

    Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information.