CVE-2018-10167: High severity tp-link eap controller vulnerability
The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4Windows/2.6.0Windows is encrypted with a hard-coded cryptographic key, so anyone who knows that key and the algorithm can decrypt it. A low-privilege user could decrypt and modify the backup file in order to elevate their privileges. This is fixed in version 2.6.1Windows.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10167?
CVE-2018-10167 has been classified as a low-severity vulnerability.
How do I fix CVE-2018-10167?
To fix CVE-2018-10167, update to the latest version of TP-Link EAP Controller that addresses this vulnerability.
Who is affected by CVE-2018-10167?
CVE-2018-10167 affects users of TP-Link EAP Controller versions 2.5.4 and 2.6.0 on Windows.
What can an attacker do with CVE-2018-10167?
An attacker with knowledge of the hard-coded cryptographic key can decrypt and modify backup files in the affected TP-Link software.
Where can I find more information about CVE-2018-10167?
For more information about CVE-2018-10167, refer to security bulletins and advisories from reliable cybersecurity sources.