← Vulnerability feed

Vulnerability record · CVE-2018-5393 · published 28 September 2018

CVE-2018-5393: Tp-link eap controller missing authentication for critical function vulnerability

Tp Link · Eap Controller

The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (RMI) service for remote control. The RMI interface does not require any authentication before use, so it lacks user authentication for RMI service commands in EAP controller versions 2.5.3 and earlier. Remote attackers can implement deserialization attacks through the RMI protocol. Successful attacks may allow a remote attacker to remotely control the target server and execute Java functions or bytecode.

9.8 CVSS 3.0 Critical EPSS 13% · top 3.8% CWE-306 · Missing authentication for critical function
9.8CVSS 3.0 base score, v2 10.0
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (RMI) service for remote control. The RMI interface does not require any authentication before use, so it lacks user authentication for RMI service commands in EAP controller versions 2.5.3 and earlier. Remote attackers can implement deserialization attacks through the RMI protocol. Successful attacks may allow a remote attacker to remotely control the target server and execute Java functions or bytecode.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/105402 Third Party AdvisoryVDB Entry
https://www.kb.cert.org/vuls/id/581311 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/105402 Third Party AdvisoryVDB Entry
https://www.kb.cert.org/vuls/id/581311 Third Party AdvisoryUS Government Resource

Track CVE-2018-5393 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-10166Tp-link eap controller cross-site request forgery vulnerabilityThe web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens i…EPSS 0.71%8.8CVE-2018-10168Tp-link eap controller improper privilege management vulnerabilityTP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of the Web API, allowing a low-p…EPSS 1.5%7.5CVE-2018-10167Tp-link eap controller hard-coded credentials vulnerabilityThe web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-code…EPSS 1.1%5.4CVE-2018-10164Tp-link eap controller cross-site scripting vulnerabilityStored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authen…EPSS 0.60%5.4CVE-2018-10165Tp-link eap controller cross-site scripting vulnerabilityStored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authen…EPSS 0.59%8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed9.3CVE-2026-72529TrueConf Server missing authentication allows remote script executionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier expose an undocumented function on port 4307/TCP …KEVEPSS 1.5%analysed

Source: NIST National Vulnerability Database (record CVE-2018-5393), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.