CVE-2025-9522 | TP-Link Omada Controller up to 5.x server-side request forgery
A vulnerability was found in TP-Link Omada Controller up to 5.x. It has been classified as critical. The impacted element is an unknown function. Performing a manipulation results in server-side request forgery.
This vulnerability is identified as CVE-2025-9522. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.