Information Disclosure Vulnerability in Omada Controller by TP-Link
CVE-2026-81531

6.9MEDIUM

What is CVE-2026-81531?

An information disclosure vulnerability has been detected in the Omada Controller, specifically within an API endpoint designed for initialization. This endpoint remains accessible even after its intended purpose is fulfilled, potentially disclosing sensitive account-related information to unauthorized users. By exploiting this vulnerability, an attacker could remotely query the endpoint, leading to the possibility of user enumeration and further targeted attacks against administrative accounts.

Affected Version(s)

OC200 V1 0

OC200 v2 0

OC200 v3 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joshua Chan, GitHub: https://github.com/popcorn94, Twitter: popc0rn94
.