CyberRota Analysis
AI-GeneratedAn information disclosure vulnerability in Omada Controller allows unauthenticated remote users to access an API endpoint intended for initialization, potentially revealing account-related information. This could enable attackers to enumerate user accounts and launch targeted attacks against administrative accounts. Organizations using Omada Controller should prioritize addressing this vulnerability to mitigate the risk of unauthorized access and account compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users. Successful exploitation may allow an attacker to remote query the affected endpoint that may facilitate user enumeration and subsequent attacks targeting administrative accounts.