<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T05:12:59.692163+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-9290</id>
    <title>CVE-2025-9290 — Authentication Weakness on Omada Controllers, Gateways and Access Points</title>
    <updated>2026-10-06T05:13:00.264277+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> TP-Link Systems Inc. Omada Software Controller, TP-Link Systems Inc. Omada Cloud Controller, TP-Link Systems Inc. Omada Hardware Controller (OC200, OC300, OC400), TP-Link Systems Inc. Omada Hardware Controller OC220, TP-Link Systems Inc. Omada Gateway (ER605 v2.0), TP-Link Systems Inc. Omada Gateway (ER7206 v2.0), TP-Link Systems Inc. Omada Gateway (ER7406, ER706W, ER706-4G), TP-Link Systems Inc. Omada Gateway (ER707-M2, ER-8411), TP-Link Systems Inc. Omada Gateway (ER7412-M2, ER706WP-4G, ER703WP-4G-Outdoor, DR3220v-4G, DR3650v, DR3650v-4G), TP-Link Systems Inc. Omada Gateway (ER8411) and 20 more</p>
<p>An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-9290"/>
  </entry>
</feed>
