CVE-2026-81531
Unauthenticated Account Information Disclosure in Multiple Omada Controllers
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users. Successful exploitation may allow an attacker to remote query the affected endpoint that may facilitate user enumeration and subsequent attacks targeting administrative accounts.
| CWE | CWE-200 |
| Vendor | tp-link system inc. |
| Product | omada software controller |
| Published | Sep 8, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link system inc. omada software controller
Be the first to know when new unknown vulnerabilities affecting tp-link system inc. omada software controller are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
TP-Link System Inc. / Omada Software Controller
0 < 6.3.0.44
TP-Link Systems Inc. / OC200 V1
0 < (UN)_V1_1.42.10 Build 20260825
TP Link Systems Inc. / OC200 v2
0 < (UN)_V2_2.27.10 Build 20260825
TP-Link Systems Inc / OC200 v3
0 < (UN)_V3_3.4.10 Build 20260825
TP-Link Systems Inc. / OC220 v1
0 < (UN)_V1_1.7.10 Build 20260825
TP-Link Systems Inc / OC220 v2
0 < (UN)_V2_2.6.10 Build 20260825
TP-Link Systems Inc. / OC300 v1
0 < (UN)_V1_1.36.10 Build 20260825
TP-Link Systems Inc. / OC400 v1
0 < (UN)_V1_1.14.10 Build 20260825
References
Credits
Joshua Chan, GitHub: https://github.com/popcorn94, Twitter: popc0rn94