CVE-2025-15629

Summary

A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation.

An attacker who successfully intercepts adoption-related communications may be able to recover session encryption keys and decrypt affected communications.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.Omada Gateways0affected
TP-Link Systems Inc.Omada Switches0affected
TP Link Systems Inc.Omada Access Points0affected
TP-Link Systems IncOmada Controllers0affected

Weaknesses

  • CWE-331: CWE-331 Insufficient entropy

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References