Omada Controller 的 SAML 单点登录(SSO)功能中存在一个信息泄露漏洞。该漏洞是由于对用户提供的 SAML 元数据校验不足所致,使得拥有 SAML 配置权限的已认证用户可以访问敏感信息。若该漏洞被成功利用,可能导致敏感信息被未授权泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | Omada Software Controller (Windows) | 0 ~ 6.2.14.11 | - |
|
| TP-Link Systems Inc. | Omada Software Controller (Linux) | 0 ~ 6.2.14.11 | - |
|
| TP-Link Systems Inc. | OC2000 v1 | 0 ~ 1.41.11 Build 20260711 | - |
|
| TP-Link Systems Inc. | OC2000 v2 | 0 ~ 2.26.11 Build 20260711 | - |
|
| TP-Link Systems Inc. | OC200 v3 | 0 ~ 3.3.11 Build 20260711 | - |
|
| TP-Link Systems Inc. | OC220 v1 | 0 ~ 1.6.11 Build 20260711 | - |
|
| TP-Link Systems Inc. | OC220 v2 | 0 ~ 2.5.11 Build 20260711 | - |
|
| TP-Link Systems Inc. | OC300 v1 | 0 ~ 1.35.11 Build 20260711 | - |
|
| TP-Link Systems Inc. | OC400 v1 | 0 ~ 1.13.11 Build 20260711 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-17176 | 7.7 HIGH | OS command injection Vulnerability in Deco BE11000 |
| CVE-2026-76653 | 5.3 MEDIUM | Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR6 |
| CVE-2026-76652 | 4.8 MEDIUM | Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL |
No comments yet