CVE-2025-9291: Improper Certificate Validation in TP-Link Omada Cloud Communications
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions.
Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9291?
CVE-2025-9291 has a high severity rating with a CVSS score of 7.7.
How do I fix CVE-2025-9291?
To mitigate CVE-2025-9291, it is recommended to update the firmware of TP-Link Omada devices to the latest version that addresses this vulnerability.
What impact does CVE-2025-9291 have on my network security?
CVE-2025-9291 can allow attackers to bypass certificate validation, potentially leading to man-in-the-middle attacks and unauthorized access to your cloud controller.
Which devices are affected by CVE-2025-9291?
CVE-2025-9291 affects the TP-Link Omada Cloud Communications devices that communicate with cloud controllers.
When was CVE-2025-9291 published?
CVE-2025-9291 was published on August 3, 2026.