Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 11 Mar 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:tp-link:omada_controller:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 27 Jan 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link omada Controller |
|
| Vendors & Products |
Tp-link
Tp-link omada Controller |
Mon, 26 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 26 Jan 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account. | |
| Title | IDOR Leading to Owner Account Hijacking in Omada Controller | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-01-26T21:11:52.235Z
Reserved: 2025-08-27T02:22:05.051Z
Link: CVE-2025-9520
Updated: 2026-01-26T21:11:44.701Z
Status : Analyzed
Published: 2026-01-26T20:16:08.770
Modified: 2026-03-11T22:43:57.723
Link: CVE-2025-9520
No data.
OpenCVE Enrichment
Updated: 2026-01-27T09:03:30Z