Impact
An information disclosure vulnerability exists in Omada Controllers whereby a post‑initialization API endpoint remains accessible after setup and can leak account‑related data to unauthenticated remote users. The flaw is defined as an information disclosure weakness (CWE‑200). Exploitation can expose user names and other administrative details, facilitating targeted attacks such as credential phishing or privilege escalation.
Affected Systems
TP Link Systems Inc. products are affected, including the Omada Software Controller and multiple OC line device firmware versions—OC200 v1, v2, v3, OC220 v1, v2, OC300 v1, and OC400 v1. All listed versions can allow an unauthenticated attacker to query the vulnerable endpoint and collect account information.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity with potential confidentiality impact. The EPSS score is not available, so the exact likelihood of exploitation is uncertain, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers would need network reach to the controller endpoint and the ability to send unauthenticated API requests; no privilege escalation or code execution is required, but the disclosed data can be leveraged for further attacks on administrative accounts.
OpenCVE Enrichment