An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.
総合評価: CVE-2025-9290 は低リスク(25.5/100)。CVSS 深刻度は中。悪用される可能性が高い(EPSS 0.02%、4 パーセンタイル) 推奨対応: 悪用情報と EPSS の推移を監視し、必要に応じて優先度を見直してください。
リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。
EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。
| # | 日付 | 旧 EPSS スコア | 新 EPSS スコア | Δ(新 − 旧) |
|---|---|---|---|---|
| 1 | 2026-01-23 | — | 0.02% | — |
EPSS の全履歴 (全 1 件)
この CVE の CVSS 指標。
| ベーススコア | バージョン | 深刻度 | ベクトル | 悪用しやすさ | 影響 | スコアの出典 |
|---|---|---|---|---|---|---|
| 6.0 | 4.0 | MEDIUM |
|
— | — | f23511db-6c3e-4e32-a477-6aa17d310630 |
| 5.9 | 3.1 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
| ベンダー | 製品 | バージョン | 生の CPE |
|---|---|---|---|
| tp-link | omada_controller | < 6.0.0.24 | cpe:2.3:a:tp-link:omada_controller:*:*:*:*:-:*:*:* |
| tp-link | omada_controller | < 6.0.0.100 | cpe:2.3:a:tp-link:omada_controller:*:*:*:*:cloud:*:*:* |
| tp-link | oc200_firmware | < 1.37.9 | cpe:2.3:o:tp-link:oc200_firmware:*:*:*:*:*:*:*:* |
| tp-link | oc220_firmware | < 1.1.3 | cpe:2.3:o:tp-link:oc220_firmware:*:*:*:*:*:*:*:* |
| tp-link | oc300_firmware | < 1.31.9 | cpe:2.3:o:tp-link:oc300_firmware:*:*:*:*:*:*:*:* |
| tp-link | oc400_firmware | < 1.9.9 | cpe:2.3:o:tp-link:oc400_firmware:*:*:*:*:*:*:*:* |
| tp-link | oc200_firmware | < 2.22.9 | cpe:2.3:o:tp-link:oc200_firmware:*:*:*:*:*:*:*:* |
| tp-link | oc220_firmware | — | cpe:2.3:o:tp-link:oc220_firmware:-:*:*:*:*:*:*:* |
| tp-link | er605_firmware | < 2.3.2 | cpe:2.3:o:tp-link:er605_firmware:*:*:*:*:*:*:*:* |
| tp-link | er7206_firmware | < 2.2.2 | cpe:2.3:o:tp-link:er7206_firmware:*:*:*:*:*:*:*:* |
| tp-link | er7406_firmware | < 1.2.2 | cpe:2.3:o:tp-link:er7406_firmware:*:*:*:*:*:*:*:* |
| tp-link | er707-m2_firmware | < 1.3.1 | cpe:2.3:o:tp-link:er707-m2_firmware:*:*:*:*:*:*:*:* |
| tp-link | er7412-m2_firmware | < 1.1.0 | cpe:2.3:o:tp-link:er7412-m2_firmware:*:*:*:*:*:*:*:* |
| tp-link | er8411_firmware | < 1.3.5 | cpe:2.3:o:tp-link:er8411_firmware:*:*:*:*:*:*:*:* |
| tp-link | er706w_firmware | < 1.2.1 | cpe:2.3:o:tp-link:er706w_firmware:*:*:*:*:*:*:*:* |
| tp-link | er706w-4g_firmware | < 1.2.1 | cpe:2.3:o:tp-link:er706w-4g_firmware:*:*:*:*:*:*:*:* |
| tp-link | er706wp-4g_firmware | < 1.1.0 | cpe:2.3:o:tp-link:er706wp-4g_firmware:*:*:*:*:*:*:*:* |
| tp-link | er703wp-4g-outdoor_firmware | < 1.1.0 | cpe:2.3:o:tp-link:er703wp-4g-outdoor_firmware:*:*:*:*:*:*:*:* |
| tp-link | dr3220v-4g_firmware | < 1.1.0 | cpe:2.3:o:tp-link:dr3220v-4g_firmware:*:*:*:*:*:*:*:* |
| tp-link | dr3650v-4g_firmware | < 1.1.0 | cpe:2.3:o:tp-link:dr3650v-4g_firmware:*:*:*:*:*:*:*:* |
| tp-link | dr3650v_firmware | < 1.1.0 | cpe:2.3:o:tp-link:dr3650v_firmware:*:*:*:*:*:*:*:* |
| tp-link | er701-5g-outdoor_firmware | < 1.0.0 | cpe:2.3:o:tp-link:er701-5g-outdoor_firmware:*:*:*:*:*:*:*:* |
| tp-link | er605w_firmware | < 2.0.2 | cpe:2.3:o:tp-link:er605w_firmware:*:*:*:*:*:*:*:* |
| tp-link | er7212pc_firmware | < 2.2.1 | cpe:2.3:o:tp-link:er7212pc_firmware:*:*:*:*:*:*:*:* |
| tp-link | fr365_firmware | < 1.1.10 | cpe:2.3:o:tp-link:fr365_firmware:*:*:*:*:*:*:*:* |
| tp-link | g36w-4g_firmware | < 1.1.5 | cpe:2.3:o:tp-link:g36w-4g_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap655-wall_firmware | < 1.6.2 | cpe:2.3:o:tp-link:eap655-wall_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap660_hd_firmware | < 1.6.1 | cpe:2.3:o:tp-link:eap660_hd_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap620_hd_firmware | < 1.6.1 | cpe:2.3:o:tp-link:eap620_hd_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap610-outdoor_firmware | < 1.6.1 | cpe:2.3:o:tp-link:eap610-outdoor_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap610_firmware | < 1.6.1 | cpe:2.3:o:tp-link:eap610_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap623-outdoor_hd_firmware | < 1.6.1 | cpe:2.3:o:tp-link:eap623-outdoor_hd_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap625-outdoor_hd_firmware | < 1.6.1 | cpe:2.3:o:tp-link:eap625-outdoor_hd_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap772_firmware | < 1.3.2 | cpe:2.3:o:tp-link:eap772_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap772-outdoor_firmware | < 1.3.2 | cpe:2.3:o:tp-link:eap772-outdoor_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap770_firmware | < 1.3.2 | cpe:2.3:o:tp-link:eap770_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap723_firmware | < 1.3.2 | cpe:2.3:o:tp-link:eap723_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap773_firmware | < 1.1.2 | cpe:2.3:o:tp-link:eap773_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap783_firmware | < 1.1.2 | cpe:2.3:o:tp-link:eap783_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap772_firmware | < 1.1.2 | cpe:2.3:o:tp-link:eap772_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap787_firmware | < 1.1.2 | cpe:2.3:o:tp-link:eap787_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap720_firmware | < 1.1.2 | cpe:2.3:o:tp-link:eap720_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap723_firmware | < 1.1.2 | cpe:2.3:o:tp-link:eap723_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap725-wall_firmware | < 1.1.2 | cpe:2.3:o:tp-link:eap725-wall_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap215_bridge_kit_firmware | < 1.1.4 | cpe:2.3:o:tp-link:eap215_bridge_kit_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap211_bridge_kit_firmware | < 1.1.4 | cpe:2.3:o:tp-link:eap211_bridge_kit_firmware:*:*:*:*:*:*:*:* |
| tp-link | beam_bridge_5_ur_firmware | < 1.1.5 | cpe:2.3:o:tp-link:beam_bridge_5_ur_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap603gp-desktop_firmware | < 1.1.0 | cpe:2.3:o:tp-link:eap603gp-desktop_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap615gp-wall_firmware | < 1.1.0 | cpe:2.3:o:tp-link:eap615gp-wall_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap625gp-wall_firmware | < 1.1.0 | cpe:2.3:o:tp-link:eap625gp-wall_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap610gp-desktop_firmware | < 1.1.0 | cpe:2.3:o:tp-link:eap610gp-desktop_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap650gp-desktop_firmware | < 1.0.1 | cpe:2.3:o:tp-link:eap650gp-desktop_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap653_firmware | < 1.3.3 | cpe:2.3:o:tp-link:eap653_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap650-outdoor_firmware | < 1.3.3 | cpe:2.3:o:tp-link:eap650-outdoor_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap230-wall_firmware | < 3.3.1 | cpe:2.3:o:tp-link:eap230-wall_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap235-wall_firmware | < 3.3.1 | cpe:2.3:o:tp-link:eap235-wall_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap603-outdoor_firmware | < 1.5.1 | cpe:2.3:o:tp-link:eap603-outdoor_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap653_ur_firmware | < 1.4.2 | cpe:2.3:o:tp-link:eap653_ur_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap650-desktop_firmware | < 1.1.0 | cpe:2.3:o:tp-link:eap650-desktop_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap615-wall_firmware | < 1.1.0 | cpe:2.3:o:tp-link:eap615-wall_firmware:*:*:*:*:*:*:*:* |
| tp-link | eap100-bridge_kit_firmware | < 1.0.3 | cpe:2.3:o:tp-link:eap100-bridge_kit_firmware:*:*:*:*:*:*:*:* |
| tp-link | er706w-4g_firmware | < 2.1.0 | cpe:2.3:o:tp-link:er706w-4g_firmware:*:*:*:*:*:*:*:* |
| tp-link | omada_controller | < 6.0.0.34 | cpe:2.3:a:tp-link:omada_controller:*:*:*:*:-:*:*:* |
| tp-link | omada_controller | < 5.15.24 | cpe:2.3:a:tp-link:omada_controller:*:*:*:*:-:*:*:* |
| URL | タグ |
|---|---|
| https://support.omadanetworks.com/en/download/ | Product |
| https://support.omadanetworks.com/us/document/114950/ | Vendor Advisory |
| https://support.omadanetworks.com/us/download/ | Product |