6

CVE-2025-9290

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-linkOmada Controller SwEdition- Version < 6.0.0.24
Tp-linkOmada Controller SwEditioncloud Version < 6.0.0.100
Tp-linkOc200 Firmware Version < 1.37.9
   Tp-linkOc200 Version1
Tp-linkOc220 Firmware Version < 1.1.3
   Tp-linkOc220 Version1
Tp-linkOc300 Firmware Version < 1.31.9
   Tp-linkOc300 Version1.6
Tp-linkOc400 Firmware Version < 1.9.9
   Tp-linkOc400 Version1.6
Tp-linkOc200 Firmware Version < 2.22.9
   Tp-linkOc200 Version2
Tp-linkOc220 Firmware Version-
   Tp-linkOc220 Version2
Tp-linkEr605 Firmware Version < 2.3.2
   Tp-linkEr605 Version2.0
Tp-linkEr7206 Firmware Version < 2.2.2
   Tp-linkEr7206 Version2.0
Tp-linkEr7406 Firmware Version < 1.2.2
   Tp-linkEr7406 Version-
Tp-linkEr707-m2 Firmware Version < 1.3.1
   Tp-linkEr707-m2 Version-
Tp-linkEr7412-m2 Firmware Version < 1.1.0
   Tp-linkEr7412-m2 Version-
Tp-linkEr8411 Firmware Version < 1.3.5
   Tp-linkEr8411 Version-
Tp-linkEr706w Firmware Version < 1.2.1
   Tp-linkEr706w Version-
Tp-linkEr706w-4g Firmware Version < 1.2.1
   Tp-linkEr706w-4g Version-
Tp-linkEr706wp-4g Firmware Version < 1.1.0
   Tp-linkEr706wp-4g Version-
Tp-linkEr703wp-4g-outdoor Firmware Version < 1.1.0
   Tp-linkEr703wp-4g-outdoor Version-
Tp-linkDr3220v-4g Firmware Version < 1.1.0
   Tp-linkDr3220v-4g Version-
Tp-linkDr3650v-4g Firmware Version < 1.1.0
   Tp-linkDr3650v-4g Version-
Tp-linkDr3650v Firmware Version < 1.1.0
   Tp-linkDr3650v Version-
Tp-linkEr701-5g-outdoor Firmware Version < 1.0.0
   Tp-linkEr701-5g-outdoor Version-
Tp-linkEr605w Firmware Version < 2.0.2
   Tp-linkEr605w Version2.0
Tp-linkEr7212pc Firmware Version < 2.2.1
   Tp-linkEr7212pc Version2.0
Tp-linkFr365 Firmware Version < 1.1.10
   Tp-linkFr365 Version-
Tp-linkG36w-4g Firmware Version < 1.1.5
   Tp-linkG36w-4g Version-
Tp-linkEap655-wall Firmware Version < 1.6.2
   Tp-linkEap655-wall Version1.0
Tp-linkEap660 Hd Firmware Version < 1.6.1
   Tp-linkEap660 Hd Version1.0
   Tp-linkEap660 Hd Version2.0
Tp-linkEap620 Hd Firmware Version < 1.6.1
   Tp-linkEap620 Hd Version3.0
   Tp-linkEap620 Hd Version3.20
Tp-linkEap610-outdoor Firmware Version < 1.6.1
   Tp-linkEap610-outdoor Version1.0
   Tp-linkEap610-outdoor Version1.20
Tp-linkEap610 Firmware Version < 1.6.1
   Tp-linkEap610 Version1.0
   Tp-linkEap610 Version2.0
Tp-linkEap623-outdoor Hd Firmware Version < 1.6.1
   Tp-linkEap623-outdoor Hd Version1.0
Tp-linkEap625-outdoor Hd Firmware Version < 1.6.1
   Tp-linkEap625-outdoor Hd Version1.0
Tp-linkEap772 Firmware Version < 1.3.2
   Tp-linkEap772 Version2.0
Tp-linkEap772-outdoor Firmware Version < 1.3.2
   Tp-linkEap772-outdoor Version1.0
Tp-linkEap770 Firmware Version < 1.3.2
   Tp-linkEap770 Version2.0
Tp-linkEap723 Firmware Version < 1.3.2
   Tp-linkEap723 Version1.0
Tp-linkEap773 Firmware Version < 1.1.2
   Tp-linkEap773 Version1.0
Tp-linkEap783 Firmware Version < 1.1.2
   Tp-linkEap783 Version1.0
Tp-linkEap772 Firmware Version < 1.1.2
   Tp-linkEap772 Version1.0
Tp-linkEap787 Firmware Version < 1.1.2
   Tp-linkEap787 Version1.0
Tp-linkEap720 Firmware Version < 1.1.2
   Tp-linkEap720 Version1.0
Tp-linkEap723 Firmware Version < 1.1.2
   Tp-linkEap723 Version2.0
Tp-linkEap725-wall Firmware Version < 1.1.2
   Tp-linkEap725-wall Version1.0
Tp-linkEap215 Bridge Kit Firmware Version < 1.1.4
   Tp-linkEap215 Bridge Kit Version3.0
Tp-linkEap211 Bridge Kit Firmware Version < 1.1.4
   Tp-linkEap211 Bridge Kit Version3.0
Tp-linkBeam Bridge 5 Ur Firmware Version < 1.1.5
   Tp-linkBeam Bridge 5 Ur Version1.0
Tp-linkEap603gp-desktop Firmware Version < 1.1.0
   Tp-linkEap603gp-desktop Version1.0
Tp-linkEap615gp-wall Firmware Version < 1.1.0
   Tp-linkEap615gp-wall Version1.0
   Tp-linkEap615gp-wall Version1.20
Tp-linkEap625gp-wall Firmware Version < 1.1.0
   Tp-linkEap625gp-wall Version1.0
   Tp-linkEap625gp-wall Version1.20
Tp-linkEap610gp-desktop Firmware Version < 1.1.0
   Tp-linkEap610gp-desktop Version1.0
   Tp-linkEap610gp-desktop Version1.20
   Tp-linkEap610gp-desktop Version1.26
Tp-linkEap650gp-desktop Firmware Version < 1.0.1
   Tp-linkEap650gp-desktop Version1.0
Tp-linkEap653 Firmware Version < 1.3.3
   Tp-linkEap653 Version1.0
Tp-linkEap650-outdoor Firmware Version < 1.3.3
   Tp-linkEap650-outdoor Version1.0
Tp-linkEap230-wall Firmware Version < 3.3.1
   Tp-linkEap230-wall Version1.0
Tp-linkEap235-wall Firmware Version < 3.3.1
   Tp-linkEap235-wall Version1.0
Tp-linkEap603-outdoor Firmware Version < 1.5.1
   Tp-linkEap603-outdoor Version1.0
Tp-linkEap653 Ur Firmware Version < 1.4.2
   Tp-linkEap653 Ur Version1.0
Tp-linkEap650-desktop Firmware Version < 1.1.0
   Tp-linkEap650-desktop Version1.0
Tp-linkEap615-wall Firmware Version < 1.1.0
   Tp-linkEap615-wall Version1.0
Tp-linkEap100-bridge Kit Firmware Version < 1.0.3
   Tp-linkEap100-bridge Kit Version1.0
Tp-linkEr706w-4g Firmware Version < 2.1.0
   Tp-linkEr706w-4g Version2.0
Tp-linkOmada Controller SwEdition- Version < 6.0.0.34
   Tp-linkOc200 Version1
   Tp-linkOc200 Version2
   Tp-linkOc300 Version1.6
   Tp-linkOc400 Version1.6
Tp-linkOmada Controller SwEdition- Version < 5.15.24
   Tp-linkOc220 Version1
   Tp-linkOc220 Version2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.069
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
f23511db-6c3e-4e32-a477-6aa17d310630 6 0 0
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-760 Use of a One-Way Hash with a Predictable Salt

The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product uses a predictable salt as part of the input.