CVE-2025-15544
Weak Credential Protection During TP-Link Omada Device Adoption
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.
| CWE | CWE-759 |
| Vendor | tp-link systems inc. |
| Product | omada gateways |
| Published | Aug 3, 2026 |
| Last Updated | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link systems inc. omada gateways
Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. omada gateways are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
TP-Link Systems Inc. / Omada Gateways
0
TP-Link Systems Inc. / Omada Switches
0
TP Link Systems Inc. / Omada Access Points
0
TP-Link Systems Inc. / Omada App
0
TP-Link Systems Inc / Omada Controllers
0
TP-Link Systems Inc / Omada OLTs
0
References
Credits
Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies