Description
An information
disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization
remains accessible after completion and may disclose account-related
information to unauthenticated remote users. 






Successful
exploitation may allow an attacker to remote query the affected endpoint that
may facilitate user enumeration and subsequent attacks targeting administrative
accounts.
Published: 2026-09-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Account Information Disclosure
Action: Apply Patch
AI Analysis

Impact

An information disclosure vulnerability exists in Omada Controllers whereby a post‑initialization API endpoint remains accessible after setup and can leak account‑related data to unauthenticated remote users. The flaw is defined as an information disclosure weakness (CWE‑200). Exploitation can expose user names and other administrative details, facilitating targeted attacks such as credential phishing or privilege escalation.

Affected Systems

TP Link Systems Inc. products are affected, including the Omada Software Controller and multiple OC line device firmware versions—OC200 v1, v2, v3, OC220 v1, v2, OC300 v1, and OC400 v1. All listed versions can allow an unauthenticated attacker to query the vulnerable endpoint and collect account information.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity with potential confidentiality impact. The EPSS score is not available, so the exact likelihood of exploitation is uncertain, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers would need network reach to the controller endpoint and the ability to send unauthenticated API requests; no privilege escalation or code execution is required, but the disclosed data can be leveraged for further attacks on administrative accounts.

Generated by OpenCVE AI on September 10, 2026 at 02:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or controller software update that includes the fix provided by TP Link.
  • If a patch is not yet available, restrict external network access to the controller or block the vulnerable API endpoint using firewall rules.
  • Enforce authentication on the controller’s APIs and consider disabling or securing the initialization endpoint through administrative settings.

Generated by OpenCVE AI on September 10, 2026 at 02:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description An information disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users.  Successful exploitation may allow an attacker to remote query the affected endpoint that may facilitate user enumeration and subsequent attacks targeting administrative accounts.
Title Unauthenticated Account Information Disclosure in Multiple Omada Controllers
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-09-21T18:01:46.384Z

Reserved: 2026-08-26T22:31:50.287Z

Link: CVE-2026-81531

cve-icon Vulnrichment

Updated: 2026-09-08T17:21:43.382Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T17:18:32.833

Modified: 2026-09-21T18:17:10.900

Link: CVE-2026-81531

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:00:09Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor