CVE-2018-5393
CVE-2018-5393 is a critical-severity vulnerability in Tp-link Eap Controller with a CVSS 3.x base score of 9.8. Its EPSS exploit-prediction score of 13% places it in the 96th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-306.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v2: 10.0
- EPSS exploit prediction: 13% (96th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-306
- Affected product: Tp-link Eap Controller
- Published:
- Last modified:
Description
The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (RMI) service for remote control. The RMI interface does not require any authentication before use, so it lacks user authentication for RMI service commands in EAP controller versions 2.5.3 and earlier. Remote attackers can implement deserialization attacks through the RMI protocol. Successful attacks may allow a remote attacker to remotely control the target server and execute Java functions or bytecode.
Frequently asked questions
- What is CVE-2018-5393?
- The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (RMI) service for remote control. The RMI interface does not require any authentication before use, so it lacks user authentication for RMI service commands in EAP controller versions 2.5.3 and earlier. Remote attackers can implement deserialization attacks through the RMI protocol. Successful attacks may allow a remote attacker to remotely control the target server and execute Java functions or bytecode.
- How severe is CVE-2018-5393?
- CVE-2018-5393 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2018-5393 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 13% (96th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2018-5393?
- CVE-2018-5393 affects Tp-link Eap Controller. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2018-5393?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2018-5393 published?
- CVE-2018-5393 was published on 2018-09-28 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:tp-link:eap_controller:*:*:*:*:*:*:*:*
More vulnerabilities in Tp-link Eap Controller
- CVE-2018-10168 — High (CVSS 8.8): TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of…
- CVE-2018-10166 — High (CVSS 8.8): The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows…
- CVE-2018-10167 — High (CVSS 7.5): The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows…
- CVE-2018-10165 — Medium (CVSS 5.4): Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions…
- CVE-2018-10164 — Medium (CVSS 5.4): Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions…
All CVEs affecting Tp-link Eap Controller →
Other CWE-306 (Missing Authentication for Critical Function) vulnerabilities
- CVE-2026-63692 — Critical (CVSS 10.0): Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function…
- CVE-2026-63688 — Critical (CVSS 10.0): Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical…
- CVE-2026-103956 — Critical (CVSS 10.0): Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed…
- CVE-2026-53988 — Critical (CVSS 10.0): Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows…
- CVE-2026-85889 — Critical (CVSS 10.0): Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges…
- CVE-2026-92808 — Critical (CVSS 10.0): A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An…
Browse all CWE-306 (Missing Authentication for Critical Function) vulnerabilities →