HIGH🇬🇧 English

CVE-2026-1668

CVSS 7.7v4.0pub. 2026-03-13upd. 2026-04-02

The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when processing crafted requests. Under specific conditions, this flaw may result in unintended command execution.<br>An unauthenticated attacker with network access to the affected interface may cause memory corruption, service instability, or information disclosure. Successful exploitation may allow remote code execution or denial-of-service.

oryginał EN
CVSS Vector
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Tp Link Omada Sg2005p Pd

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg2005p Pd Firmware

    OS
    Tp-Link
    1.0.0 – 1.0.19 (bez)
  • Tp Link Omada Sg2008

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg2008 Firmware

    OS
    Tp-Link
    4.20.0 – 4.20.17 (bez)4.30.0 – 4.30.1 (bez)
  • Tp Link Omada Sg2008p

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg2008p Firmware

    OS
    Tp-Link
    3.30.0 – 3.30.1 (bez)3.20.0 – 3.20.17 (bez)
  • Tp Link Omada Sg2016p

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg2016p Firmware

    OS
    Tp-Link
    1.20.0 – 1.20.17 (bez)1.30.0 – 1.30.1 (bez)
  • Tp Link Omada Sg2210mp

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg2210mp Firmware

    OS
    Tp-Link
    4.20.0 – 4.20.18 (bez)5.0.0 – 5.0.15 (bez)5.20.0 – 5.20.1 (bez)
  • Tp Link Omada Sg2210p

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg2210p Firmware

    OS
    Tp-Link
    5.20.0 – 5.20.18 (bez)5.30.0 – 5.30.1 (bez)
  • Tp Link Omada Sg2210xmp M2

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg2210xmp M2 Firmware

    OS
    Tp-Link
    1.0.0 – 1.0.19 (bez)
  • Tp Link Omada Sg2218

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg2218 Firmware

    OS
    Tp-Link
    1.20.0 – 1.20.17 (bez)1.30.0 – 1.30.1 (bez)
  • Tp Link Omada Sg2218p

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg2218p Firmware

    OS
    Tp-Link
    2.0.0 – 2.0.14 (bez)1.20.0 – 1.20.17 (bez)2.20.0 – 2.20.2 (bez)
  • Tp Link Omada Sg2428lp

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg2428lp Firmware

    OS
    Tp-Link
    1.0.0 – 1.0.13 (bez)
  • Tp Link Omada Sg2428p

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg2428p Firmware

    OS
    Tp-Link
    5.30.0 – 5.30.16 (bez)5.20.0 – 5.20.20 (bez)
  • Tp Link Omada Sg2452lp

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg2452lp Firmware

    OS
    Tp-Link
    1.0.0 – 1.0.13 (bez)
  • Tp Link Omada Sg3210

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg3210 Firmware

    OS
    Tp-Link
    3.20.0 – 3.20.17 (bez)3.30.0 – 3.30.1 (bez)
  • Tp Link Omada Sg3210xhp M2

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg3210xhp M2 Firmware

    OS
    Tp-Link
    3.0.0 – 3.0.21 (bez)
  • Tp Link Omada Sg3210x M2

    HW
    Tp-Link
    wszystkie wersje
  • Tp Link Omada Sg3210x M2 Firmware

    OS
    Tp-Link
    1.20.0 – 1.20.1 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCEAuth Bypass
CWE
Referencje

Powiązane podatności

CVE-2025-15628HIGH8.2PL ✓ten sam produkt

Omada: współdzielone certyfikaty umożliwiają podszywanie się pod kontrolery

CVE-2025-9291HIGH7.7PL ✓ten sam produkt

Omada: błąd weryfikacji certyfikatu TLS umożliwia atak man-in-the-middle

CVE-2025-15544MEDIUM6.9ten sam produkt

A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credent...

CVE-2025-15630MEDIUM5.8ten sam produkt

A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to inter...

CVE-2025-15631MEDIUM5.7ten sam produkt

A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy ...