Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gwgw-6q3h-28pg

Опубликовано: 23 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6

Описание

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.

EPSS

Процентиль: 2%
0.00015
Низкий

6 Medium

CVSS4

Дефекты

CWE-760

Связанные уязвимости

nvd
13 дней назад

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.

CVSS3: 5.3
fstec
14 дней назад

Уязвимость микропрограммного обеспечения сетевых шлюзов TP-Link Omada, связанная с использованием одностороннего хеширования с предсказуемыми случайными данными, позволяющая нарушителю получить несанкционированный доступ к конфиденциальной информации

EPSS

Процентиль: 2%
0.00015
Низкий

6 Medium

CVSS4

Дефекты

CWE-760