Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gwgw-6q3h-28pg

Опубликовано: 23 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6
CVSS3: 5.9

Описание

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.

EPSS

Процентиль: 10%
0.00201
Низкий

6 Medium

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-760

Связанные уязвимости

CVSS3: 5.9
nvd
7 месяцев назад

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.

CVSS3: 5.3
fstec
7 месяцев назад

Уязвимость микропрограммного обеспечения сетевых шлюзов TP-Link Omada, связанная с использованием одностороннего хеширования с предсказуемыми случайными данными, позволяющая нарушителю получить несанкционированный доступ к конфиденциальной информации

EPSS

Процентиль: 10%
0.00201
Низкий

6 Medium

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-760