TP-Link Omada Cloud Controller
cpe:2.3:o:tp-link:omada_controller:*:*:*:*:*:*:*
- < 4.25.25
A permissive web security configuration in TP-Link Omada cloud controllers prior to version 4.25.25 may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could lead to the unauthorized disclosure of sensitive information.
Exploitation of this vulnerability could result in the unauthorized disclosure of sensitive information.
Users with affected Omada Cloud deployments do not need to take any action, as updates are automatically applied to the cloud environment once validated by TP-Link.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.