Vulnerability Database

322,573

Total vulnerabilities in the database

CVE-2025-9289

A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker could execute arbitrary JavaScript in the administrator’s browser, potentially exposing sensitive information and compromising confidentiality.

  • Published: Jan 22, 2026
  • Updated: Jan 23, 2026
  • CVE: CVE-2025-9289
  • Exploit:

No technical information available.