Impersonation Vulnerability in TP-Link Omada Devices
CVE-2025-15628
8.2HIGH
Key Information:
- Vendor
Tp-link Systems Inc.
- Vendor
- CVE Published:
- 3 August 2026
What is CVE-2025-15628?
The vulnerability in TP-Link Omada devices arises from the use of shared embedded certificates that establish trust between controllers and managed devices. If an attacker compromises these embedded certificates, they can potentially impersonate legitimate controllers or devices. This exploitation could enable the attacker to intercept sensitive communications, posing a significant risk to the integrity of network operations. It is essential for users to apply patches and secure their deployments to mitigate this threat.
Affected Version(s)
Omada Access Points 0
Omada Controllers 0
Omada Gateways 0
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies
