PT-2022-1817 · Tp Link · Tp-Link Omada Sdn Software Controller

Published

2022-03-07

·

Updated

2022-07-12

·

CVE-2021-44032

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions TP-Link Omada SDN Software Controller versions prior to 5.0.15
Description The issue is related to errors in processing authentication requests in the TP-Link Omada SDN software controller. This can allow a remote attacker to gain access to a protected network by bypassing the captive portal authentication process. For instance, an attacker can exploit this by setting window.authType=0 in client-side JavaScript, effectively using a downgraded "no authentication" method.
Recommendations For versions prior to 5.0.15, update to version 5.0.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the authentication method to prevent bypassing the captive portal authentication process.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01247
CVE-2021-44032

Affected Products

Tp-Link Omada Sdn Software Controller