Back

MEDIUM

Authentication Weakness on Omada Controllers, Gateways and Access Points

Published Jan 22, 2026

Description

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (1)
  1. EUVD
    • Updated

      changed from Jan 23, 2026 to Oct 6, 2026

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TPLink
Published Jan 22, 2026
Updated Oct 6, 2026
Reserved Aug 20, 2025
CISA Vulnrichment
Updated Jan 23, 2026
NVD
Status Analyzed
Modified Oct 7, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner TPLink
Published Jan 22, 2026
Updated Oct 6, 2026
Exploited since n/a
EUVD-2026-4495