Description
The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when processing crafted requests. Under specific conditions, this flaw may result in unintended command execution.<br>An unauthenticated attacker with network access to the affected interface may cause memory corruption, service instability, or information disclosure. Successful exploitation may allow remote code execution or denial-of-service.
Problem types
CWE-20 Improper Input Validation
Product status
Any version before 3.20.17 Build 20260121 Rel.53429
Any version before 3.30.1 Build 20260127 Rel.32017
Any version before 1.30.1 Build 20260129 Rel.8831
Any version before 1.20.16 Build 20260121 Rel.57953
Any version before 2.40.1 Build 20260127 Rel.39545
Any version before 3.30.1 Build 20260127 Rel.39545
Any version before 1.40.1 Build 20260127 Rel.39545
Any version before 1.30.1 Build 20260127 Rel.39545
Any version before 3.40.1 Build 20260128 Rel.7041
Any version before 6.30.1 Build 20260127 Rel.39545
Any version before 2.20.2 Build 20260127 Rel.32017
Any version before 1.30.1 Build 20260127 Rel.32017
Any version before 2.30.1 Build 20260128 Rel.8721
Any version before 1.20.1 Build 20260127 Rel.39545
Any version before 1.30.1 Build 20260128 Rel.8721
Any version before 4.30.1 Build 20260127 Rel.32017
Any version before 3.30.1 Build 20260206 Rel.33103
Any version before 5.20.1 Build 20260127 Rel.32017
Any version before 5.30.1 Build 20260127 Rel.32017
Any version before 1.30.1 Build 20260127 Rel.32017
Any version before 1.30.1 Build 20260128 Rel.7041
Any version before 1.20.1 Build 20260129 Rel.13605
Any version before 1.0.19 Build 20260121 Rel.53314
Any version before 4.20.17 Build 20260121 Rel.53429
Any version before 1.20.17 Build 20260121 Rel.53429
Any version before 3.20.17 Build 20260121 Rel.53429
Any version before 1.20.18 Build 20260121 Rel.54271
Any version before 1.0.11 Build 20260121 Rel.56907
Any version before 1.20.17 Build 20260121 Rel.53429
Any version before 1.0.12 Build 20260121 Rel.56907
Any version before 1.0.15 Build 20260121 Rel.53429
Any version before 6.20.18 Build 20260121 Rel.53429
Any version before 1.0.19 Build 20260121 Rel.53314
Any version before 3.0.21 Build 20260121 Rel.53314
Any version before 2.0.14 Build 20260121 Rel.53429
Any version before 1.0.19 Build 20260121 Rel.53314
Any version before 5.30.16 Build 20260121 Rel.53429
Any version before 4.20.18 Build 20260121 Rel.53429
Any version before 3.30.17 Build 20260121 Rel.54132
Any version before 1.20.17 Build 20260121 Rel.54132
Any version before 1.0.13 Build 20260121 Rel.54132
Any version before 1.0.15 Build 20260121 Rel.56907
Any version before 1.20.18 Build 20260121 Rel.55833
Any version before 1.0.15 Build 20260121 Rel.55833
Any version before 1.20.19 Build 20260121 Rel.54271
Any version before 3.0.22 Build 20260121 Rel.54132
Any version before 5.20.20 Build 20260121 Rel.53429
Any version before 5.0.15 Build 20260121 Rel.53429
Any version before 1.0.19 Build 20260121 Rel.53429
Any version before 1.20.17 Build 20260121 Rel.53429
Any version before 2.20.20 Build 20260121 Rel.55833
Any version before 3.20.21 Build 20260113 Rel.67732
Any version before 1.30.17 Build 20260113 Rel.67732
Any version before 1.20.16 Build 20260113 Rel.67732
Any version before 6.20.20 Build 20260113 Rel.67732
Any version before 5.0.25 Build 20260113 Rel.67732
Any version before 2.30.16 Build 20260113 Rel.67732
Any version before 1.0.16 Build 20260113 Rel.67732
Any version before 4.0.26 Build 20260121 Rel.53429
Any version before 5.20.18 Build 20260121 Rel.53429
Any version
Any version
Credits
tangrs
References
support.omadanetworks.com/us/product/
support.omadanetworks.com/au/download/firmware/
support.omadanetworks.com/en/download/firmware/
support.omadanetworks.com/us/document/118794/