← Back

CVE-2025-9292

nvd nist
Published: Feb 13, 2026Modified: Jun 17, 2026

JSON object

Loading...
2.0
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: f23511db-6c3e-4e32-a477-6aa17d310630 (Secondary)

Description

A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow unauthorized disclosure of sensitive information. Fixed in updated Omada Cloud Controller service versions deployed automatically by TP‑Link. No user action is required.

Affected (14)

14 products
Aginet
Deco
Festa
Kasa
Kidshield
Omada
Omada Guard
Tapo
Tether
Tp Partner
Tpcamera
Vigi
Wi Fi Navi
Wifi Toolkit
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.13.6
Before 3.9.163
Before 1.7.1
Before 3.4.350
Before 1.1.21
Before 4.25.25
Before 1.1.28
Before 3.14.111
Before 4.12.27
Before 2.0.1
Before 3.2.17
Before 2.7.70
Before 1.5.5
Before 1.4.28

References (2)

Source: f23511db-6c3e-4e32-a477-6aa17d310630
Vendor Advisory
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Vendor Advisory

Timeline

No history available yet.