Junglewise Threat Intelligence

CVE-2026-81531: TP-Link Omada Controller API information disclosure in controller initialization

CVE-2026-81531 · Severity: info · CVSS 6.9 · Published 2026-09-08

Vendors: TP-Link.

Executive brief

Omada Controller is a centralized management platform for TP-Link network devices including access points, switches, and routers. An API endpoint used during initial setup remains accessible after configuration is complete, allowing unauthenticated attackers to query account information remotely. This vulnerability enables attackers to enumerate administrative accounts and launch targeted attacks against controller administrator credentials.

Technical details

An information disclosure vulnerability exists in Omada Controller where an API endpoint designed for controller initialization remains accessible after setup completion. The vulnerability allows unauthenticated remote users to query this endpoint without authentication, potentially exposing account-related information including administrative user details. The attack requires only network access to the affected endpoint (AV:N, AC:L, PR:N, UI:N) and enables user enumeration to facilitate subsequent targeted attacks on administrative accounts. TP-Link has released patches in version 6.3.0.45 for Windows/Linux software controllers and various firmware updates (build 20260825) for hardware controller models.

Affected products

  • TP-Link Omada Controller before 6.3.0.45
  • TP-Link OC200(UN) V1 before 1.42.10 Build 20260825, V2 before 2.27.10 Build 20260825, V3 before 3.4.10 Build 20260825
  • TP-Link OC220(UN) V1 before 1.7.10 Build 20260825, V2 before 2.6.10 Build 20260825
  • TP-Link OC300(UN) V1 before 1.36.10 Build 20260825
  • TP-Link OC400(UN) V1 before 1.14.10 Build 20260825

Timeline

  • 2026-09-08: disclosed: CVE-2026-81531 published on NVD
  • 2026-09-21: advisory: TP-Link security advisory released with CVSS score and affected versions
  • 2026-09-04: patched: Software Controller version 6.3.0.45 release date

References