VendorsTP-Linkomada_controllerall versions
Vulnerabilities

TP-Link Omada Controller

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2025-9520
IDOR Leading to Owner Account Hijacking in Omada Controller
Published 2026-01-26 · Analyzed
8.3EPSS 0.004
CVE-2025-9521
Password Confirmation Bypass in Omada Controller
Published 2026-01-26 · Analyzed
6.5EPSS 0.003
CVE-2025-9290
Authentication Weakness on Omada Controllers, Gateways and Access Points
Published 2026-01-22 · Analyzed
6.0EPSS 0.002
CVE-2025-9289
Cross-Site Scripting (XSS) on Omada Controllers
Published 2026-01-22 · Analyzed
5.7EPSS 0.002
CVE-2020-12475
TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.portal.PortalController.getAdvertiseFile in /opt/tplink/EAPController/lib/eap-web-3.2.6.jar.
Published 2020-05-04 · Modified
5.5EPSS 0.006
CVE-2025-9522
Blind Server-Side Request Forgery (SSRF) in Omada Controller
Published 2026-01-26 · Analyzed
5.3EPSS 0.003