CVE-2025-9521: TP-Link Omada Controller

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security.

Affected products

  • TP-Link Omada Controller: before 6.0 (fixed in 6.0)

Published 2026-01-26. Last modified 2026-06-17.