Tp-link
Tp-link Omada Controller: vulnerabilidades y CVE
Tp-link Omada Controller tiene 8 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses7
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-84941 | Media (6.9) | 0.47% | — | 11 sept 2026 | An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to… |
| CVE-2026-81531 | Media (6.9) | 0.67% | — | 8 sept 2026 | An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to… |
| CVE-2025-9522 | Media (5.1) | 0.28% | — | 26 ene 2026 | Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information. |
| CVE-2025-9521 | Baja (2.1) | 0.32% | — | 26 ene 2026 | Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to… |
| CVE-2025-9520 | Alta (8.3) | 0.45% | — | 26 ene 2026 | An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account. |
| CVE-2025-9290 | Media (6) | 0.22% | — | 23 ene 2026 | An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and… |
| CVE-2025-9289 | Media (5.7) | 0.20% | — | 22 ene 2026 | A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a… |
| CVE-2020-12475 | Media (5.5) | 0.56% | — | 4 may 2020 | TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.portal.PortalController.getAdvertiseFile in /opt/tplink/EAPController/lib/eap-web-3.2.6.jar. |