HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Antigravity CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
  4. CVE 2025 9290 authentication weakness on omada controllers
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Servers
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright ยฉ 2026 HOL DAO LLC. All rights reserved.

Back to active CVEs
Medium ยท CVSS 6.0CVE-2025-9290

Authentication Weakness on Omada Controllers, Gateways and Access PointsCVE-2025-9290

Answer in brief

CVE-2025-9290 records a Medium severity (CVSS 6.0) vulnerability in Authentication Weakness on Omada Controllers, Gateways and Access Points. The current sources do not mark it as known exploited. The current feed maps TP-Link Systems Inc./Omada Access Point (EAP215 Bridge KIT 3.0, EAP211 Bridge KIT 3.0) (generic), TP-Link Systems Inc./Omada Access Point (EAP230-Wall v1.0, EAP235-Wall v1.0) (generic), TP-Link Systems Inc./Omada Access Point (EAP603GP-Desktop, EAP615GP-Wall 1.20, EAP625GP-Wall 1.0/1.20, EAP610GP-Desktop 1.0/1.20/1.26), EAP650-Desktop v1.0) (generic), TP-Link Systems Inc./Omada Access Point (EAP603-Outdoor v1.0, EAP615-Wall v1.0/v1.20) (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.

Analysis pending evidence review

HOL Guard separates source facts from reviewed analysis. See the methodology.

Published Jan 22, 2026Updated Oct 6, 2026Source checked Oct 7, 2026First seen by HOL Oct 6, 2026Material review Oct 6, 2026
Upstream Advisory

Key facts

Risk
Medium ยท CVSS 6.0
Exploitation
Not marked as known exploited
Affected software
30 mapped packages or products
Fix availability
Available

Why this deserves its current priority

CVSS is 6.0. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.

Analysis status

Analysis pending evidence review

Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.

Affected scope and exposure questions

The current feed maps TP-Link Systems Inc./Omada Access Point (EAP215 Bridge KIT 3.0, EAP211 Bridge KIT 3.0) (generic), TP-Link Systems Inc./Omada Access Point (EAP230-Wall v1.0, EAP235-Wall v1.0) (generic), TP-Link Systems Inc./Omada Access Point (EAP603GP-Desktop, EAP615GP-Wall 1.20, EAP625GP-Wall 1.0/1.20, EAP610GP-Desktop 1.0/1.20/1.26), EAP650-Desktop v1.0) (generic), TP-Link Systems Inc./Omada Access Point (EAP603-Outdoor v1.0, EAP615-Wall v1.0/v1.20) (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.

Mapped affected packages and fixed versions
PackageAffected rangeFixed version
TP-Link Systems Inc./Omada Access Point (EAP215 Bridge KIT 3.0, EAP211 Bridge KIT 3.0)generic>=0 <1.1.4 Build 20251112 Rel.347691.1.4 Build 20251112 Rel.34769, 1.1.4
TP-Link Systems Inc./Omada Access Point (EAP230-Wall v1.0, EAP235-Wall v1.0)generic>=0 <3.3.1 Build 20251203 Rel.581353.3.1 Build 20251203 Rel.58135, 3.3.1
TP-Link Systems Inc./Omada Access Point (EAP603GP-Desktop, EAP615GP-Wall 1.20, EAP625GP-Wall 1.0/1.20, EAP610GP-Desktop 1.0/1.20/1.26), EAP650-Desktop v1.0)generic>=0 <1.1.01.1.0
TP-Link Systems Inc./Omada Access Point (EAP603-Outdoor v1.0, EAP615-Wall v1.0/v1.20)generic>=0 <1.5.11.5.1
TP-Link Systems Inc./Omada Access Point (EAP615-Wall v1.0/v1.20)generic>=0 <1.5.10 Build 20250903 Rel.497841.5.10 Build 20250903 Rel.49784, 1.5.10
TP-Link Systems Inc./Omada Access Point (EAP650GP-Desktop 1.0)generic>=0 <1.0.1 Build 20250819 Rel.602981.0.1 Build 20250819 Rel.60298, 1.0.1
TP-Link Systems Inc./Omada Access Point (EAP653 UR v1.0)generic>=0 <1.4.2 Build 20251208 Rel.438301.4.2 Build 20251208 Rel.43830, 1.4.2
TP-Link Systems Inc./Omada Access Point (EAP653 v1.0, EAP650-Outdoor v1.0)generic>=0 <1.3.3 Build 20251111 Rel.726271.3.3 Build 20251111 Rel.72627, 1.3.3
TP-Link Systems Inc./Omada Access Point (EAP655-Wall v1.0)generic>=0 <1.6.2 Build 20251107 Rel.357001.6.2 Build 20251107 Rel.35700, 1.6.2
TP-Link Systems Inc./Omada Access Point (EAP660 HD v1.0/v2.0, EAP620 HD v2.0/v3.0/v3.20, EAP610/EAP610-Outdoor v1.0/v2.0, EAP623-Outdoor HD v1.0, EAP625-Outdoor HD v1.0)EAPgeneric>=0 <1.6.11.6.1
TP-Link Systems Inc./Omada Access Point (EAP723 v1.0, EAP772 v2.0, EAP772-Outdoor v 1.0, EAP770 v2.0)generic>=0 <1.3.2 Build 20250901 Rel.522551.3.2 Build 20250901 Rel.52255, 1.3.2
TP-Link Systems Inc./Omada Access Point (EAP772 v1.0, EAP773 v1.0, EAP783 v1.0, EAP787 v1.0, EAP720 v1.0, EAP725-Wall v1.0, EAp723 v2.0)generic>=0 <1.1.21.1.2
TP-Link Systems Inc./Omada Beam Bridge 5 UR v1.0generic>=0 <1.1.5 Build 20250928 Rel.684991.1.5 Build 20250928 Rel.68499, 1.1.5
TP-Link Systems Inc./Omada Cloud Controllergeneric>=0 <6.0.0.1006.0.0.100
TP-Link Systems Inc./Omada EAP100-Bridge KIT v1.0generic>=0 <1.0.3 Build 20251015 Rel.620581.0.3 Build 20251015 Rel.62058, 1.0.3
TP-Link Systems Inc./Omada Festa Gateway FR365generic>=0 <1.1.10 Build 20250626 Rel.817461.1.10 Build 20250626 Rel.81746, 1.1.10
TP-Link Systems Inc./Omada Gateway (ER605 v2.0)generic>=0 <2.3.2 Build 20251029 Rel.127272.3.2 Build 20251029 Rel.12727, 2.3.2
TP-Link Systems Inc./Omada Gateway (ER605W 2.0)generic>=0 <2.0.2 Build 20250723 Rel.390482.0.2 Build 20250723 Rel.39048, 2.0.2
TP-Link Systems Inc./Omada Gateway (ER701-5G-Outdoor)generic>=0 <1.0.0 Build 20250826 Rel.688621.0.0 Build 20250826 Rel.68862, 1.0.0
TP-Link Systems Inc./Omada Gateway (ER706W-4G 2.0)generic>=0 <2.1.0 Build 20250810 Rel.770202.1.0 Build 20250810 Rel.77020, 2.1.0
TP-Link Systems Inc./Omada Gateway (ER707-M2, ER-8411)generic>=0 <1.3.x1.3.x
TP-Link Systems Inc./Omada Gateway (ER7206 v2.0)generic>=0 <2.2.2 Build 20250724 Rel.111092.2.2 Build 20250724 Rel.11109, 2.2.2
TP-Link Systems Inc./Omada Gateway ER7212PC 2.0generic>=0 <2.2.1 Build 20251027 Rel.751292.2.1 Build 20251027 Rel.75129, 2.2.1
TP-Link Systems Inc./Omada Gateway (ER7406, ER706W, ER706-4G)generic>=0 <1.2.x1.2.x
TP-Link Systems Inc./Omada Gateway (ER7412-M2, ER706WP-4G, ER703WP-4G-Outdoor, DR3220v-4G, DR3650v, DR3650v-4G)generic>=0 <1.1.01.1.0
TP-Link Systems Inc./Omada Gateway (ER8411)generic>=0 <1.3.5 Build 20251028 Rel.068111.3.5 Build 20251028 Rel.06811, 1.3.5
TP-Link Systems Inc./Omada Gateway G36W-4Ggeneric>=0 <1.1.5 Build 20250710 Rel.621421.1.5 Build 20250710 Rel.62142, 1.1.5
TP-Link Systems Inc./Omada Hardware Controller (OC200, OC300, OC400)generic>=0 <6.0.0.346.0.0.34
TP-Link Systems Inc./Omada Hardware Controller OC220generic>=0 <5.15.245.15.24
TP-Link Systems Inc./Omada Software Controllergeneric>=0 <6.0.0.246.0.0.24

Recommended response

  1. 1Check inventory. Check lockfiles and deployed manifests for TP-Link Systems Inc./Omada Access Point (EAP215 Bridge KIT 3.0, EAP211 Bridge KIT 3.0), TP-Link Systems Inc./Omada Access Point (EAP230-Wall v1.0, EAP235-Wall v1.0), TP-Link Systems Inc./Omada Access Point (EAP603GP-Desktop, EAP615GP-Wall 1.20, EAP625GP-Wall 1.0/1.20, EAP610GP-Desktop 1.0/1.20/1.26), EAP650-Desktop v1.0).
  2. 2Review the reported fix. Update TP-Link Systems Inc./Omada Access Point (EAP215 Bridge KIT 3.0, EAP211 Bridge KIT 3.0) to 1.1.4 Build 20251112 Rel.34769; TP-Link Systems Inc./Omada Access Point (EAP230-Wall v1.0, EAP235-Wall v1.0) to 3.3.1 Build 20251203 Rel.58135; TP-Link Systems Inc./Omada Access Point (EAP603GP-Desktop, EAP615GP-Wall 1.20, EAP625GP-Wall 1.0/1.20, EAP610GP-Desktop 1.0/1.20/1.26), EAP650-Desktop v1.0) to 1.1.0; TP-Link Systems Inc./Omada Access Point (EAP603-Outdoor v1.0, EAP615-Wall v1.0/v1.20) to 1.5.1; TP-Link Systems Inc./Omada Access Point (EAP615-Wall v1.0/v1.20) to 1.5.10 Build 20250903 Rel.49784; TP-Link Systems Inc./Omada Access Point (EAP650GP-Desktop 1.0) to 1.0.1 Build 20250819 Rel.60298; TP-Link Systems Inc./Omada Access Point (EAP653 UR v1.0) to 1.4.2 Build 20251208 Rel.43830; TP-Link Systems Inc./Omada Access Point (EAP653 v1.0, EAP650-Outdoor v1.0) to 1.3.3 Build 20251111 Rel.72627; TP-Link Systems Inc./Omada Access Point (EAP655-Wall v1.0) to 1.6.2 Build 20251107 Rel.35700; TP-Link Systems Inc./Omada Access Point (EAP660 HD v1.0/v2.0, EAP620 HD v2.0/v3.0/v3.20, EAP610/EAP610-Outdoor v1.0/v2.0, EAP623-Outdoor HD v1.0, EAP625-Outdoor HD v1.0)EAP to 1.6.1; TP-Link Systems Inc./Omada Access Point (EAP723 v1.0, EAP772 v2.0, EAP772-Outdoor v 1.0, EAP770 v2.0) to 1.3.2 Build 20250901 Rel.52255; TP-Link Systems Inc./Omada Access Point (EAP772 v1.0, EAP773 v1.0, EAP783 v1.0, EAP787 v1.0, EAP720 v1.0, EAP725-Wall v1.0, EAp723 v2.0) to 1.1.2; TP-Link Systems Inc./Omada Beam Bridge 5 UR v1.0 to 1.1.5 Build 20250928 Rel.68499; TP-Link Systems Inc./Omada Cloud Controller to 6.0.0.100; TP-Link Systems Inc./Omada EAP100-Bridge KIT v1.0 to 1.0.3 Build 20251015 Rel.62058; TP-Link Systems Inc./Omada Festa Gateway FR365 to 1.1.10 Build 20250626 Rel.81746; TP-Link Systems Inc./Omada Gateway (ER605 v2.0) to 2.3.2 Build 20251029 Rel.12727; TP-Link Systems Inc./Omada Gateway (ER605W 2.0) to 2.0.2 Build 20250723 Rel.39048; TP-Link Systems Inc./Omada Gateway (ER701-5G-Outdoor) to 1.0.0 Build 20250826 Rel.68862; TP-Link Systems Inc./Omada Gateway (ER706W-4G 2.0) to 2.1.0 Build 20250810 Rel.77020; TP-Link Systems Inc./Omada Gateway (ER707-M2, ER-8411) to 1.3.x; TP-Link Systems Inc./Omada Gateway (ER7206 v2.0) to 2.2.2 Build 20250724 Rel.11109; TP-Link Systems Inc./Omada Gateway ER7212PC 2.0 to 2.2.1 Build 20251027 Rel.75129; TP-Link Systems Inc./Omada Gateway (ER7406, ER706W, ER706-4G) to 1.2.x; TP-Link Systems Inc./Omada Gateway (ER7412-M2, ER706WP-4G, ER703WP-4G-Outdoor, DR3220v-4G, DR3650v, DR3650v-4G) to 1.1.0; TP-Link Systems Inc./Omada Gateway (ER8411) to 1.3.5 Build 20251028 Rel.06811; TP-Link Systems Inc./Omada Gateway G36W-4G to 1.1.5 Build 20250710 Rel.62142; TP-Link Systems Inc./Omada Hardware Controller (OC200, OC300, OC400) to 6.0.0.34; TP-Link Systems Inc./Omada Hardware Controller OC220 to 5.15.24; TP-Link Systems Inc./Omada Software Controller to 6.0.0.24 if you use the affected versions. Test the change in a non-production environment first.

Evidence timeline and material changes

  1. Published upstream

    Jan 22, 2026

    Evidence: source:cvelist:source_dates:source-dates:record
  2. Source modified

    Oct 6, 2026

    Evidence: source:cvelist:source_dates:source-dates:record
  3. First seen by HOL

    Oct 6, 2026

Sources and claim methodology

  • Source referencesupport.omadanetworks.com
  • Source referencesupport.omadanetworks.com
  • Source referencesupport.omadanetworks.com
Upstream source description

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.

Quoted source text, attributed separately from HOL analysis.

Related CVEs

  • Gitea OAuth2 refresh token grant accepts access tokensSame generic ecosystem
  • Langflow OSS is affected by multiple vulnerabilitiesSame generic ecosystem
  • Langflow OSS is affected by multiple vulnerabilitiesSame generic ecosystem
  • Langflow OSS is affected by multiple vulnerabilitiesSame generic ecosystem
  • Langflow OSS is affected by multiple vulnerabilitiesSame generic ecosystem
  • Langflow OSS is affected by multiple vulnerabilitiesSame generic ecosystem

Record context

Vulnerability class
Missing Auth
EPSS
Not reported
CWE IDs
CWE-760
Source
CVE List V5
Source checked
Oct 7, 2026
References
3 linked sources
Open source record