CVE-2025-9290
Published Jan 23, 2026An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requ…
Vendor/product archive
5 CVEs tagged to tp-link / er706w — 2 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requ…
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.