CVE-2025-9522: TP-Link Omada Controller
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information.
Affected products
- TP-Link Omada Controller: before 6.0 (fixed in 6.0)
Published 2026-01-26. Last modified 2026-06-17.