CVE-2026-81531
Last modified
CVE-2026-81531 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users. Successful exploitation may allow an attacker to remote query the affected endpoint that may facilitate user enumeration and subsequent attacks targeting administrative accounts.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users. Successful exploitation may allow an attacker to remote query the affected endpoint that may facilitate user enumeration and subsequent attacks targeting administrative accounts.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| TP-Link System Inc. | Omada Software Controller | < 6.3.0.44 |
| TP-Link Systems Inc. | OC200 V1 | < (UN)_V1_1.42.10 Build 20260825 |
| TP Link Systems Inc. | OC200 v2 | < (UN)_V2_2.27.10 Build 20260825 |
| TP-Link Systems Inc | OC200 v3 | < (UN)_V3_3.4.10 Build 20260825 |
| TP-Link Systems Inc. | OC220 v1 | < (UN)_V1_1.7.10 Build 20260825 |
| TP-Link Systems Inc | OC220 v2 | < (UN)_V2_2.6.10 Build 20260825 |
| TP-Link Systems Inc. | OC300 v1 | < (UN)_V1_1.36.10 Build 20260825 |
| TP-Link Systems Inc. | OC400 v1 | < (UN)_V1_1.14.10 Build 20260825 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-81531?
How severe is CVE-2026-81531?
How do I fix CVE-2026-81531?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81526The MongoDB Rust Driver does not neutralize special characte…6.5
- CVE-2026-81527A NoSQL/expression injection weakness exists in the LINQ-to-…6.5
- CVE-2026-81528A MongoDB C# driver document-replacement code path omits the…5.4
- CVE-2026-81529Improper neutralization of delimiters in connection-URL cons…7.1
- CVE-2026-8153OS command injection in Dashboard Server interface in Univer…9.8
- CVE-2026-81530A weakness in the client-side encryption configuration surfa…5.6
- CVE-2026-81532A user able to submit SQL through an application using the M…8.8
- CVE-2026-81533An application using the MongoDB BI Connector ODBC Driver ma…7.1
- CVE-2026-81540IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a re…8.5
- CVE-2026-81543The Abandoned Cart Pro for WooCommerce plugin for WordPress …8.8
- CVE-2026-81546The Affinity by Canva application before 3.3.0 (September 20…7.7
- CVE-2026-8155The BuddyPress WordPress plugin before 14.5.0 does not prope…5.4
Are you affected by CVE-2026-81531?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
