CVE-2025-15628

Summary

Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices.

An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.Omada Gateways0affected
TP-Link Systems Inc.Omada Switches0affected
TP Link Systems Inc.Omada Access Points0affected
TP-Link Systems IncOmada Controllers0affected
TP-Link Systems Inc.Omada OLTs0affected

Weaknesses

  • CWE-798: CWE-798 Use of Hard-coded Credentials

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References