Skip to main content

Vendor/product archive

tp-link / omada_controller CVEs

Beta · best-effort

6 CVEs tagged to tp-link / omada_controller0 Critical, 1 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2025-9522

Published Jan 26, 2026

Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of infor…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-9521

Published Jan 26, 2026

Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password w…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9520

Published Jan 26, 2026

An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12475

Published May 4, 2020

TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.portal.PortalController.getAdvertiseFile in /opt/tplink/EAPC…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1