PT-2018-9729 · Tp Link · Tp-Link Eap Controller+1

Published

2018-05-03

·

Updated

2018-06-12

·

CVE-2018-10167

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: TP-Link EAP Controller and Omada Controller versions 2.5.4 Windows through 2.6.0 Windows
Description: The issue concerns the encryption of the web application backup file, which uses a hard-coded cryptographic key. This allows anyone with knowledge of the key and algorithm to decrypt the file. A low-privilege user can exploit this to decrypt and modify the backup file, potentially elevating their privileges.
Recommendations: For versions 2.5.4 Windows through 2.6.0 Windows, update to version 2.6.1 Windows to resolve the issue.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10167

Affected Products

Omada Controller
Tp-Link Eap Controller