- EPSS 15.74%
- Published 28.09.2018 17:29:00
- Last modified 21.11.2024 04:08:44
The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (RMI) service for remote control. The RMI interface does not require any authentication before use, s...
CVE-2018-10164
- EPSS 0.3%
- Published 03.05.2018 18:29:00
- Last modified 21.11.2024 03:40:55
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implementation of portalPictureUploa...
CVE-2018-10165
- EPSS 0.26%
- Published 03.05.2018 18:29:00
- Last modified 21.11.2024 03:40:55
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userName parameter in the local user...
CVE-2018-10166
- EPSS 0.4%
- Published 03.05.2018 18:29:00
- Last modified 21.11.2024 03:40:55
The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any forms. This would allow an attacker to submit authenticated requests when an authenticated user...
CVE-2018-10167
- EPSS 0.46%
- Published 03.05.2018 18:29:00
- Last modified 21.11.2024 03:40:56
The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-coded cryptographic key, so anyone who knows that key and the algorithm can decrypt it. A low-privilege u...
CVE-2018-10168
- EPSS 0.62%
- Published 03.05.2018 18:29:00
- Last modified 21.11.2024 03:40:56
TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of the Web API, allowing a low-privilege user to make any request as an Administrator. This is fixed in version 2.6.1_Windows.