Tp-link

Eap Controller

6 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 15.74%
  • Published 28.09.2018 17:29:00
  • Last modified 21.11.2024 04:08:44

The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (RMI) service for remote control. The RMI interface does not require any authentication before use, s...

Exploit
  • EPSS 0.3%
  • Published 03.05.2018 18:29:00
  • Last modified 21.11.2024 03:40:55

Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implementation of portalPictureUploa...

Exploit
  • EPSS 0.26%
  • Published 03.05.2018 18:29:00
  • Last modified 21.11.2024 03:40:55

Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userName parameter in the local user...

Exploit
  • EPSS 0.4%
  • Published 03.05.2018 18:29:00
  • Last modified 21.11.2024 03:40:55

The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any forms. This would allow an attacker to submit authenticated requests when an authenticated user...

Exploit
  • EPSS 0.46%
  • Published 03.05.2018 18:29:00
  • Last modified 21.11.2024 03:40:56

The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-coded cryptographic key, so anyone who knows that key and the algorithm can decrypt it. A low-privilege u...

Exploit
  • EPSS 0.62%
  • Published 03.05.2018 18:29:00
  • Last modified 21.11.2024 03:40:56

TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of the Web API, allowing a low-privilege user to make any request as an Administrator. This is fixed in version 2.6.1_Windows.