Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Omada/
  3. Omada Identity Omada Identity Cloud

Omada Identity Omada Identity Cloud

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 42 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~40 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

SaaS IGA platform with AI-powered automation for identity lifecycle management

by Omada · omadaidentity.com · source ↗

Known CVEs (42)7 newAbout this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2025-15631 ↗MEDIUM 5.9new2026

    A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who ob…

  • CVE-2025-15630 ↗MEDIUM 5.9new2026

    A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resultin…

  • CVE-2025-15629 ↗HIGH 7.5new2026

    A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficie…

  • CVE-2025-15628 ↗HIGH 7.5new2026

    Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certif…

  • CVE-2025-15627 ↗HIGH 7.5new2026

    A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and ma…

  • CVE-2025-15544 ↗MEDIUM 5.9new2026

    A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that d…

  • CVE-2025-9291 ↗MEDIUM 6.5new2026

    A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certif…

  • CVE-2026-1668 ↗CRITICAL 9.82026

    The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when processing crafted requests. Under specific condit…

  • CVE-2025-7375 ↗MEDIUM 6.52026

    A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cause the device’s HTTP service to crash. This result…

  • CVE-2025-9292 ↗HIGH 7.52026

    A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing …

  • CVE-2025-9522 ↗MEDIUM 5.32026

    Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information.

  • CVE-2025-9521 ↗MEDIUM 6.52026

    Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirm…

  • CVE-2025-9520 ↗MEDIUM 6.82026

    An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.

  • CVE-2025-9290 ↗MEDIUM 5.92026

    An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network…

  • CVE-2025-9289 ↗MEDIUM 4.72026

    A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning…

  • CVE-2025-7851 ↗CRITICAL 9.82025

    An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.

  • CVE-2025-7850 ↗HIGH 7.22025

    A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.

  • CVE-2024-52951 ↗HIGH 8.02024

    Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a speci…

  • CVE-2024-21827 ↗HIGH 7.22024

    A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network reques…

  • CVE-2024-5244 ↗MEDIUM 4.22024

    TP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerability. This vulnerability allows network-adjacent attackers to access or spoof DDNS messages on affected installations of TP-Link Oma…

  • …and 22 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Identity & Access Management products

see all →
  • 1Password Extended Access Management · 1Password
  • AD Guardian Cloud · CionSystems
  • ARCON Privileged Access Management · ARCON
  • Abbey Labs · Abbey Labs
  • Aceiss · Aceiss
  • Active Directory Permissions Analyzer · Paramount Defenses
  • Adaptive MFA · Okta
  • Adaxes · softerra adaxes