5.7

CVE-2025-9289

A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker could execute arbitrary JavaScript in the administrator’s browser, potentially exposing sensitive information and compromising confidentiality.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-linkOmada Controller SwEdition- Version < 6.0.0.24
Tp-linkOmada Controller SwEditioncloud Version < 6.0.0.100
Tp-linkOc200 Firmware Version < 1.37.9
   Tp-linkOc200 Version1
Tp-linkOc220 Firmware Version < 1.2.9
   Tp-linkOc220 Version1
Tp-linkOc300 Firmware Version < 1.31.9
   Tp-linkOc300 Version1.6
Tp-linkOc400 Firmware Version < 1.9.9
   Tp-linkOc400 Version1.6
Tp-linkOc200 Firmware Version < 2.22.9
   Tp-linkOc200 Version2
Tp-linkOmada Controller SwEdition- Version < 6.0.0.34
   Tp-linkOc200 Version1
   Tp-linkOc200 Version2
   Tp-linkOc220 Version1
   Tp-linkOc300 Version1.6
   Tp-linkOc400 Version1.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.012
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.7 1.6 2.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
f23511db-6c3e-4e32-a477-6aa17d310630 5.7 0 0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.