CVE-2021-44032
Summary
| CVE | CVE-2021-44032 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-10 17:44:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | TP-Link Omada SDN Software Controller before 5.0.15 does not check if the authentication method specified in a connection request is allowed. An attacker can bypass the captive portal authentication process by using the downgraded "no authentication" method, and access the protected network. For example, the attacker can simply set window.authType=0 in client-side JavaScript. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tp-link | Omada Software Controller | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-repository/POC_CVE-2021-44032_Kevin.md at master · Orange-Cyberdefense/CVE-repository · GitHub | MISC | github.com | |
| Omada Cloud Software Defined Networking (SDN) | Cloud Centralized Management | TP-Link | MISC | www.tp-link.com | |
| TP-Link - Security Advisory | TP-Link | MISC | www.tp-link.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.