High-Severity IDOR Flaw Lets Admins Hijack TP-Link Omada Owner Accounts
ID: 93a67c22-8249-5d9b-b02f-439c2adf0096
STIX ID: report--93a67c22-8249-5d9b-b02f-439c2adf0096
Feed Name: securityonline.info
TP-Link issued an advisory detailing three vulnerabilities in Omada Controller: CVE-2025-9520 (IDOR, CVSS 8.3) which can allow an Administrator to take over the Owner account and gain full control of the management plane; CVE-2025-9521 (Password Confirmation Bypass, Low) that lets an attacker with a valid session change passwords without secondary confirmation; and CVE-2025-9522 (Blind SSRF, Medium) in webhook functionality that may permit internal service enumeration. Administrators should check affected versions and apply updates immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
