CVE-2025-9290CWE-760

Authentication Weakness on Omada Controllers, Gateways and Access Points

Medium · published January 22, 2026

CVSS v4.0
6.0
EPSS
0%
Percentile
11.3
In the wild
Unconfirmed
What it is

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.

The record
Technical detail
CVSS v4.0
6.0 · MEDIUM
Vector
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00211 · 11.3th percentile
Weakness
CWE-760 · Use of a One-Way Hash with a Predictable Salt
Published
2026-01-22T23:14Z
EPSS history
Timeline
  • 22 JAN 23:14Z
    Authentication Weakness on Omada Controllers, Gateways and Access Points
    cvelistv5