CVE-2025-9292
Permissive Web Security Policy Allows Cross-Origin Access Control Bypass on Omada Cloud Controllers
Description
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow unauthorized disclosure of sensitive information. Fixed in updated Omada Cloud Controller service versions deployed automatically by TP‑Link. No user action is required.
CVSS Vector Breakdown
AV:NAccess VectorAC:LAccess ComplexityC:LConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-9292 and every CVE in our database. Create a free account — no credit card required.
Create Free Account