Cryptographic Weakness in Omada Devices by TP-Link
CVE-2025-15631

5.7MEDIUM

What is CVE-2025-15631?

A cryptographic weakness has been identified in certain Omada devices from TP-Link, where stored site credentials are secured using an outdated hashing algorithm. This weak protection may allow unauthorized users to access sensitive credential data. If attackers successfully retrieve this data, they can potentially recover valid credentials, leading to unauthorized access to the affected devices or their management environments. Users are advised to apply available patches and updates to enhance their device's security.

Affected Version(s)

Omada Access Points 0

Omada Gateways 0

Omada OLTs 0

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies
.