Impact
An authenticated user with SAML configuration privileges can inject XML external entities validate the supplied metadata, allowing the extraction of local files. This results in the attacker reading sensitive files on the controller host, exposing configuration data or credentials.
Affected Systems
TP‑Link Systems Inc. Omada Controller software for Linux and Windows, and various OC firmware revisions – OC200 v3, OC2000 v1, OC2000 v2, OC220 v1, OC220 v2, OC300 v1, and OC400 v1.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9. No EPSS value is published, and the flaw is not listed in CISA's KEV catalog. Exploitation requires an authenticated user with SAML configuration rights; thus the attack vector is internal, following the likelihood that such privileges exist within an organization. Given the documented local file read capability, the impact is moderate but could allow discovery of private data.
OpenCVE Enrichment