CVE-2025-9289: TP-Link OC200 Firmware

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker could execute arbitrary JavaScript in the administrator’s browser, potentially exposing sensitive information and compromising confidentiality.

Affected products

  • TP-Link OC200 Firmware: before 1.37.9 (fixed in 1.37.9); before 2.22.9 (fixed in 2.22.9)
  • TP-Link OC220 Firmware: before 1.2.9 (fixed in 1.2.9)
  • TP-Link OC300 Firmware: before 1.31.9 (fixed in 1.31.9)
  • TP-Link OC400 Firmware: before 1.9.9 (fixed in 1.9.9)
  • TP-Link Omada Controller: before 6.0.0.24 (fixed in 6.0.0.24); before 6.0.0.100 (fixed in 6.0.0.100); before 6.0.0.34 (fixed in 6.0.0.34)

Published 2026-01-22. Last modified 2026-06-17.