Home
HIGH: 8.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:LDefault status
unknown
Any version before 6.0
affected
Description
An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version before 6.0
Credits
Eduardo Bido on behalf of Thoropass
References
support.omadanetworks.com/us/document/115200/
support.omadanetworks.com/...load/software/omada-controller/