PT-2026-87186 · Tp Link Systems · Oc200 V1+7

CVE-2026-81531

·

Published

2026-09-08

·

Updated

2026-09-08

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
An information disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users. 
Successful exploitation may allow an attacker to remote query the affected endpoint that may facilitate user enumeration and subsequent attacks targeting administrative accounts.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81531

Affected Products

Oc200 V1
Oc200 V2
Oc200 V3
Oc220 V1
Oc220 V2
Oc300 V1
Oc400 V1
Omada Software Controller