← Back

Omada

omada

Vendor: Tp Link • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
113Omada
Omada Ds1008x FirmwareOmada Ds1016g Firmware+110 more
Aug 7, 2026
Aug 3, 2026
6.9 MEDIUM· v4
5.9 MEDIUM· v3
N/A· v2
A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide suff...Show more
A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.Show less
1Tp Link
14Aginet
DecoFesta+11 more
Jun 17, 2026
Feb 13, 2026
7.7 HIGH· v4
8.1 HIGH· v3
N/A· v2
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able...Show more
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel. Successful exploitation may compromise confidentiality, integrity, and availability of application data.Show less
1Tp Link
14Aginet
DecoFesta+11 more
Jun 17, 2026
Feb 13, 2026
2.0 LOW· v4
7.5 HIGH· v3
N/A· v2
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injectio...Show more
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow unauthorized disclosure of sensitive information. Fixed in updated Omada Cloud Controller service versions deployed automatically by TP‑Link. No user action is required.Show less