CVE-2025-9520: TP-Link Omada Controller
Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.
An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.
Affected products
- TP-Link Omada Controller: before 6.0 (fixed in 6.0)
Published 2026-01-26. Last modified 2026-06-17.