logo

High-Severity IDOR Flaw Lets Admins Hijack TP-Link Omada Owner Accounts

ID: 93a67c22-8249-5d9b-b02f-439c2adf0096

STIX ID: report--93a67c22-8249-5d9b-b02f-439c2adf0096

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-29

Date Updated: 2026-04-23

Author: Ddos

...
...

TP-Link issued an advisory detailing three vulnerabilities in Omada Controller: CVE-2025-9520 (IDOR, CVSS 8.3) which can allow an Administrator to take over the Owner account and gain full control of the management plane; CVE-2025-9521 (Password Confirmation Bypass, Low) that lets an attacker with a valid session change passwords without secondary confirmation; and CVE-2025-9522 (Blind SSRF, Medium) in webhook functionality that may permit internal service enumeration. Administrators should check affected versions and apply updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.