Mongobleed
Dear Team,
Does the security issue reported for Mongo CVE-2025-14847 also apply for the software-based Omada controller?
One recommendation offered to remedy - in case no immediate update to a patched version is possible - was to close down port 27217 which is however necessary for the Omada controller to run.
Or not relevant as also not mentioned in the port forwarding section in the configuration document https://support.omadanetworks.com/uy/document/13090/ ?
Thanks!
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
If you are running omada on an ubuntu server you can upgrade mongodb, it is not possible with the windows installation since mongodb is built into the omada package, there are two versions either 3.6.23 and 7.0.14, both of which are covered by the threat.

- Copy Link
- Report Inappropriate Content
If you are running omada on an ubuntu server you can upgrade mongodb, it is not possible with the windows installation since mongodb is built into the omada package, there are two versions either 3.6.23 and 7.0.14, both of which are covered by the threat.

- Copy Link
- Report Inappropriate Content
@MR.S Thx.
Have seen the recommendation to hotfix. Windows seems to be a problem then.
- Copy Link
- Report Inappropriate Content
Hi @Eg64
Thanks for the feedback.
You may have a look at the following:
Security Advisory on Omada Controller Exposure to MongoBleed (CVE-2025-14847)
- Copy Link
- Report Inappropriate Content
Thanks for the update!
Have also found a hint in the release notes for the 6.2.9.19 version of the controller.
Br's
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 413
Replies: 5
Voters 0
No one has voted for it yet.
