Cross-Site Request Forgery Vulnerability in TP-Link EAP and Omada Controllers
CVE-2018-10166

8.8HIGH

Key Information:

Vendor
Tp-link
Vendor
CVE Published:
3 May 2018

Summary

The web management interface of TP-Link's EAP Controller and Omada Controller lacks anti-CSRF tokens, exposing users to the risk of unauthorized requests. An attacker can exploit this flaw by directing an authenticated user to a malicious site, where the user's credentials can be leveraged to perform actions without their consent. This vulnerability underscores the importance of implementing security measures such as CSRF tokens to safeguard against potential exploits. A fix is available in version 2.6.1_Windows.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.