🔐 CVE Alert

CVE-2026-81531

UNKNOWN 0.0

Unauthenticated Account Information Disclosure in Multiple Omada Controllers

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An information disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users.  Successful exploitation may allow an attacker to remote query the affected endpoint that may facilitate user enumeration and subsequent attacks targeting administrative accounts.

CWE CWE-200
Vendor tp-link system inc.
Product omada software controller
Published Sep 8, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for tp-link system inc. omada software controller

Be the first to know when new unknown vulnerabilities affecting tp-link system inc. omada software controller are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

TP-Link System Inc. / Omada Software Controller
0 < 6.3.0.44
TP-Link Systems Inc. / OC200 V1
0 < (UN)_V1_1.42.10 Build 20260825
TP Link Systems Inc. / OC200 v2
0 < (UN)_V2_2.27.10 Build 20260825
TP-Link Systems Inc / OC200 v3
0 < (UN)_V3_3.4.10 Build 20260825
TP-Link Systems Inc. / OC220 v1
0 < (UN)_V1_1.7.10 Build 20260825
TP-Link Systems Inc / OC220 v2
0 < (UN)_V2_2.6.10 Build 20260825
TP-Link Systems Inc. / OC300 v1
0 < (UN)_V1_1.36.10 Build 20260825
TP-Link Systems Inc. / OC400 v1
0 < (UN)_V1_1.14.10 Build 20260825

References

NVD ↗ CVE.org ↗ EPSS Data ↗
support.omadanetworks.com: https://support.omadanetworks.com/us/download/software/omada-controller/ support.omadanetworks.com: https://support.omadanetworks.com/us/document/133567/ support.omadanetworks.com: https://support.omadanetworks.com/en/download/software/omada-controller/

Credits

Joshua Chan, GitHub: https://github.com/popcorn94, Twitter: popc0rn94