Tp-link

Omada Software Controller

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 10.09.2026 23:35:53
  • Zuletzt bearbeitet 11.09.2026 15:21:12

An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied...

  • EPSS 0.2%
  • Veröffentlicht 22.01.2026 23:14:45
  • Zuletzt bearbeitet 07.10.2026 00:17:19

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept a...

Medienbericht
  • EPSS 0.17%
  • Veröffentlicht 22.01.2026 21:48:35
  • Zuletzt bearbeitet 16.03.2026 18:06:44

A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interacti...

Exploit
  • EPSS 1.79%
  • Veröffentlicht 10.03.2022 17:44:13
  • Zuletzt bearbeitet 21.11.2024 06:30:15

TP-Link Omada SDN Software Controller before 5.0.15 does not check if the authentication method specified in a connection request is allowed. An attacker can bypass the captive portal authentication process by using the downgraded "no authentication"...