TP-Link / Eap Controller
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-5393 | TP-Link EAP Controller versions 2.5.3 and earlier lack RMI authentication | CRITICAL | 9.8 | Sep 28, 2018 |
| CVE-2018-10168 | TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of the Web API, allowing a low-privilege u… | HIGH | 8.8 | May 3, 2018 |
| CVE-2018-10167 | The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-coded cryptogr… | HIGH | 7.5 | May 3, 2018 |
| CVE-2018-10166 | The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any form… | HIGH | 8.8 | May 3, 2018 |
| CVE-2018-10165 | Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated at… | MEDIUM | 5.4 | May 3, 2018 |
| CVE-2018-10164 | Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated at… | MEDIUM | 5.4 | May 3, 2018 |
Showing 1 to 6 of 6 CVEs