Cryptographic Weakness in Device Adoption Process for TP-Link Omada Products
CVE-2025-15544
6.9MEDIUM
Key Information:
- Vendor
Tp-link Systems Inc.
- Vendor
- CVE Published:
- 3 August 2026
What is CVE-2025-15544?
A cryptographic weakness in the TP-Link Omada device adoption process raises significant security concerns. During the adoption phase, authentication credentials associated with site management are transmitted using a weak hashing algorithm that lacks adequate protection. This vulnerability potentially allows an attacker, who successfully intercepts the adoption-related authentication traffic, to recover valid credentials, thereby gaining unauthorized access to managed devices or controller-managed environments. It is crucial for users of Omada products to address this issue promptly by applying necessary patches and updates.
Affected Version(s)
Omada Access Points 0
Omada App 0
Omada Controllers 0
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies
