TP-Link Omada Controller
cpe:2.3:o:tp-link:omada_controller:*:*:*:*:*:*:*
- < 6.0
A password confirmation bypass vulnerability has been identified in Omada Controllers, affecting versions prior to 6.0. This vulnerability allows an attacker with a valid session token to bypass secondary verification processes when changing a user's password. As a result, the password can be altered without proper confirmation, leading to a reduction in account security.
Exploitation of this vulnerability could allow an attacker to change a user's password without authorization, potentially leading to unauthorized access to the user's account.
Users are advised to update to version 6.0 or later. The latest version can be downloaded from the Omada Network Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.