CVE-2025-15544

Summary

A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection.

An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.Omada Gateways0affected
TP-Link Systems Inc.Omada Switches0affected
TP Link Systems Inc.Omada Access Points0affected
TP-Link Systems Inc.Omada App0affected
TP-Link Systems IncOmada Controllers0affected
TP-Link Systems IncOmada OLTs0affected

Weaknesses

  • CWE-759: CWE-759 Use of a One-Way hash without a salt

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References