SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2025-9291

MEDIUM · CVSS 6.5 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

Affected Omada devices exhibit a weakness in certificate identity verification, failing to ensure that the presented certificate matches the expected cloud controller hostname. This vulnerability could enable attackers to intercept or modify communications between the devices and cloud controllers. Organizations utilizing Omada devices should prioritize addressing this issue to safeguard their network integrity and prevent potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-9291
Severity
MEDIUM
CVSS
6.5
EPSS
0.13%

Original NVD Description

A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers.

Related CVEs

Other vulnerabilities affecting the same vendor(s)