An information
disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization
remains accessible after completion and may disclose account-related
information to unauthenticated remote users.
Successful
exploitation may allow an attacker to remote query the affected endpoint that
may facilitate user enumeration and subsequent attacks targeting administrative
accounts.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users. Successful exploitation may allow an attacker to remote query the affected endpoint that may facilitate user enumeration and subsequent attacks targeting administrative accounts. | |
| Title | Unauthenticated Account Information Disclosure in Multiple Omada Controllers | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published: 2026-09-08T16:53:18.786Z
Updated: 2026-09-08T17:21:54.913Z
Reserved: 2026-08-26T22:31:50.287Z
Link: CVE-2026-81531
Updated: 2026-09-08T17:21:43.382Z
Status : Deferred
Published: 2026-09-08T17:18:32.833
Modified: 2026-09-08T19:15:18.627
Link: CVE-2026-81531
No data.