Cryptographic Weakness in Omada Adoption Protocol by TP-Link
CVE-2025-15629

6.9MEDIUM

What is CVE-2025-15629?

A cryptographic weakness has been identified in the Omada adoption protocol utilized by TP-Link, wherein the generation of session encryption keys lacks sufficient entropy. This deficiency may enable an attacker who intercepts adoption-related communications to potentially recover the session encryption keys, leading to the decryption of secured communications between controllers and managed devices. Organizations using Omada products should prioritize reviewing their configurations and applying any available security patches to mitigate the risk.

Affected Version(s)

Omada Access Points 0

Omada Controllers 0

Omada Gateways 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies
.