disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization
remains accessible after completion and may disclose account-related
information to unauthenticated remote users.
Successful
exploitation may allow an attacker to remote query the affected endpoint that
may facilitate user enumeration and subsequent attacks targeting administrative
accounts.
Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 09 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users. Successful exploitation may allow an attacker to remote query the affected endpoint that may facilitate user enumeration and subsequent attacks targeting administrative accounts. | |
| Title | Unauthenticated Account Information Disclosure in Multiple Omada Controllers | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-09-08T17:21:54.913Z
Reserved: 2026-08-26T22:31:50.287Z
Link: CVE-2026-81531
Updated: 2026-09-08T17:21:43.382Z
Status : Deferred
Published: 2026-09-08T17:18:32.833
Modified: 2026-09-08T19:15:18.627
Link: CVE-2026-81531
No data.
OpenCVE Enrichment
No data.