PT-2018-9729 · Tp Link · Tp-Link Eap Controller+1
Published
2018-05-03
·
Updated
2018-06-12
·
CVE-2018-10167
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
TP-Link EAP Controller and Omada Controller versions 2.5.4 Windows through 2.6.0 Windows
Description:
The issue concerns the encryption of the web application backup file, which uses a hard-coded cryptographic key. This allows anyone with knowledge of the key and algorithm to decrypt the file. A low-privilege user can exploit this to decrypt and modify the backup file, potentially elevating their privileges.
Recommendations:
For versions 2.5.4 Windows through 2.6.0 Windows, update to version 2.6.1 Windows to resolve the issue.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Omada Controller
Tp-Link Eap Controller