CVE-2026-81531
Deferred
Deferred - Pending Action
Information Disclosure in Omada Controller
Vulnerability report for CVE-2026-81531, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-08
Last updated on: 2026-09-08
Assigner: TPLink
Description
Description
An information
disclosure vulnerability has been identified in Omada Controller.Β An API endpoint intended for Controller initialization
remains accessible after completion and may disclose account-related
information to unauthenticated remote users.Β
Successful
exploitation may allow an attacker to remote query the affected endpoint that
may facilitate user enumeration and subsequent attacks targeting administrative
accounts.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| omada_controller | omada_controller | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |