CVE-2025-15630

Summary

A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker.

Successful exploitation may allow disclosure of provisioning information intended for a legitimate device.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.Omada Gateways0affected
TP-Link Systems Inc.Omada Switches0affected
TP Link Systems Inc.Omada Access Points0affected
TP-Link Systems IncOmada Controllers0affected

Weaknesses

  • CWE-362: CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References