Cryptographic Weakness in Device Adoption Process for TP-Link Omada Products
CVE-2025-15544

6.9MEDIUM

What is CVE-2025-15544?

A cryptographic weakness in the TP-Link Omada device adoption process raises significant security concerns. During the adoption phase, authentication credentials associated with site management are transmitted using a weak hashing algorithm that lacks adequate protection. This vulnerability potentially allows an attacker, who successfully intercepts the adoption-related authentication traffic, to recover valid credentials, thereby gaining unauthorized access to managed devices or controller-managed environments. It is crucial for users of Omada products to address this issue promptly by applying necessary patches and updates.

Affected Version(s)

Omada Access Points 0

Omada App 0

Omada Controllers 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies
.