CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information. |
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to we...Show more |
An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account. |
1Tp Link 56Beam Bridge 5 Ur Firmware Dr3220v 4g FirmwareDr3650v 4g Firmware+53 moreJun 17, 2026 Jan 23, 2026 6.0 MEDIUM· v4 5.9 MEDIUM· v3 N/A· v2 An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and all...Show more |
1Tp Link 5Oc200 Firmware Oc220 FirmwareOc300 Firmware+2 moreJun 17, 2026 Jan 22, 2026 5.7 MEDIUM· v4 4.7 MEDIUM· v3 N/A· v2 A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trus...Show more |
TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.portal.PortalController.getAdvertiseFile in /opt/tplink/EAPController/lib/eap-web-3.2.6.jar. |