CVE-2025-15631

Summary

A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection.

An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.Omada Gateways0affected
TP-Link Systems Inc.Omada Switches0affected
TP Link Systems Inc.Omada Access Points0affected
TP-Link Systems Inc.Omada OLTs0affected

Weaknesses

  • CWE-759: CWE-759 Use of a One-Way hash without a salt

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References