CVE-2025-9292
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow unauthorized disclosure of sensitive information. Fixed in updated Omada Cloud Controller service versions deployed automatically by TP‑Link. No user action is required.
Published:Feb 13, 2026
Last Modified:Apr 1, 2026
EPS:Feb 13, 2026
EPSS Score:0.00017
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Tp-link
Product
Aginet
Tp-link
Aginet
Vendor
Tp-link
Product
Deco
Tp-link
Deco
Vendor
Tp-link
Product
Festa
Tp-link
Festa
Vendor
Tp-link
Product
Kasa
Tp-link
Kasa
Vendor
Tp-link
Product
Kidshield
Tp-link
Kidshield
Vendor
Tp-link
Product
Omada
Tp-link
Omada
Vendor
Tp-link
Product
Omada Cloud Controller
Tp-link
Omada Cloud Controller
Vendor
Tp-link
Product
Omada Guard
Tp-link
Omada Guard
Vendor
Tp-link
Product
Tapo
Tp-link
Tapo
Vendor
Tp-link
Product
Tether
Tp-link
Tether
Vendor
Tp-link
Product
Tp-partner
Tp-link
Tp-partner
Vendor
Tp-link
Product
Tpcamera
Tp-link
Tpcamera
Vendor
Tp-link
Product
Vigi
Tp-link
Vigi
Vendor
Tp-link
Product
Wi-fi Navi
Tp-link
Wi-fi Navi
Vendor
Tp-link
Product
Wifi Toolkit
Tp-link
Wifi Toolkit
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
