Impersonation Vulnerability in TP-Link Omada Devices
CVE-2025-15628

8.2HIGH

What is CVE-2025-15628?

The vulnerability in TP-Link Omada devices arises from the use of shared embedded certificates that establish trust between controllers and managed devices. If an attacker compromises these embedded certificates, they can potentially impersonate legitimate controllers or devices. This exploitation could enable the attacker to intercept sensitive communications, posing a significant risk to the integrity of network operations. It is essential for users to apply patches and secure their deployments to mitigate this threat.

Affected Version(s)

Omada Access Points 0

Omada Controllers 0

Omada Gateways 0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies
.