Information Disclosure Vulnerability in Omada Controller by TP-Link
CVE-2026-81531
6.9MEDIUM
Key Information:
- Vendor
Tp-link System Inc.
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-81531?
An information disclosure vulnerability has been detected in the Omada Controller, specifically within an API endpoint designed for initialization. This endpoint remains accessible even after its intended purpose is fulfilled, potentially disclosing sensitive account-related information to unauthorized users. By exploiting this vulnerability, an attacker could remotely query the endpoint, leading to the possibility of user enumeration and further targeted attacks against administrative accounts.
Affected Version(s)
OC200 V1 0
OC200 v2 0
OC200 v3 0
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Joshua Chan, GitHub: https://github.com/popcorn94, Twitter: popc0rn94
