Aller au contenu

Fiche vulnérabilité

CVE-2021-44032 : faille élevée tp-link omada software controller (CVSS 7.5)

Description

TP-Link Omada SDN Software Controller before 5.0.15 does not check if the authentication method specified in a connection request is allowed. An attacker can bypass the captive portal authentication process by using the downgraded "no authentication" method, and access the protected network. For example, the attacker can simply set window.authType=0 in client-side JavaScript.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
10 mars 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • tp-link omada software controller

Références

Rechercher une autre vulnérabilité dans la base CVE