Race Condition in Omada Device Adoption Process by TP-Link
CVE-2025-15630

5.8MEDIUM

What is CVE-2025-15630?

A race condition vulnerability exists in TP-Link's cloud-based Omada device adoption process. This flaw allows an attacker to potentially interact with the device adoption workflow before a legitimate device completes its registration. As a result, provisioning information intended for legitimate devices may be disclosed to an unauthorized party. This poses a significant security risk as it may allow attackers to gain access to sensitive setup configurations and network information, compromising the integrity of the network.

Affected Version(s)

Omada Access Points 0

Omada Controllers 0

Omada Gateways 0

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies
.