VYPR
Vendor

Omada Networks

Products
6
CVEs
15
Across products
15
Status
Private

Products

6

Recent CVEs

15
  • CVE-2026-19586CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.06

    A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide…

  • CVE-2026-1668CriMar 13, 2026
    risk 0.64cvss 9.8epss 0.01

    The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when processing crafted requests. Under specific conditions, this flaw may result in unintended command execution.An…

  • CVE-2025-7851CriOct 21, 2025
    risk 0.64cvss 9.8epss 0.01

    An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.

  • CVE-2025-9292HigFeb 13, 2026
    risk 0.49cvss 7.5epss 0.00

    A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web…

  • CVE-2026-19683HigAug 20, 2026
    risk 0.48cvss 7.4epss 0.00

    A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an…

  • CVE-2025-7850HigOct 21, 2025
    risk 0.47cvss 7.2epss 0.03

    A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.

  • CVE-2026-84941MedSep 11, 2026
    risk 0.45cvss epss 0.00

    An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful…

  • CVE-2026-81531MedSep 8, 2026
    risk 0.45cvss epss 0.00

    An information disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users.  Successful…

  • CVE-2025-9520MedJan 26, 2026
    risk 0.44cvss 6.8epss 0.00

    An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.

  • CVE-2025-7375MedMar 5, 2026
    risk 0.42cvss 6.5epss 0.00

    A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cause the device’s HTTP service to crash. This results in temporary service unavailability until the device is rebooted. This…

  • CVE-2025-9521MedJan 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security.

  • CVE-2025-9290MedJan 23, 2026
    risk 0.38cvss 5.9epss 0.00

    An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge…

  • CVE-2025-9522MedJan 26, 2026
    risk 0.34cvss 5.3epss 0.00

    Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information.

  • CVE-2025-9289MedJan 22, 2026
    risk 0.31cvss 4.7epss 0.00

    A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated…

  • CVE-2026-9033MedAug 20, 2026
    risk 0.28cvss 4.3epss 0.00

    An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access.  …