CVE-2025-15629
Weak Session Key Generation in TP-Link Omada Adoption Protocol
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be able to recover session encryption keys and decrypt affected communications.
| CWE | CWE-331 |
| Vendor | tp-link systems inc. |
| Product | omada gateways |
| Published | Aug 3, 2026 |
| Last Updated | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link systems inc. omada gateways
Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. omada gateways are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TP-Link Systems Inc. / Omada Gateways
0
TP-Link Systems Inc. / Omada Switches
0
TP Link Systems Inc. / Omada Access Points
0
TP-Link Systems Inc / Omada Controllers
0
References
Credits
Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies