Race Condition in Omada Device Adoption Process by TP-Link
CVE-2025-15630
5.8MEDIUM
Key Information:
- Vendor
Tp-link Systems Inc.
- Vendor
- CVE Published:
- 3 August 2026
What is CVE-2025-15630?
A race condition vulnerability exists in TP-Link's cloud-based Omada device adoption process. This flaw allows an attacker to potentially interact with the device adoption workflow before a legitimate device completes its registration. As a result, provisioning information intended for legitimate devices may be disclosed to an unauthorized party. This poses a significant security risk as it may allow attackers to gain access to sensitive setup configurations and network information, compromising the integrity of the network.
Affected Version(s)
Omada Access Points 0
Omada Controllers 0
Omada Gateways 0
References
CVSS V4
Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies
