CVE-2025-15630
Device Provisioning Race Condition in TP-Link Omada Adoption Workflow
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of provisioning information intended for a legitimate device.
| CWE | CWE-362 |
| Vendor | tp-link systems inc. |
| Product | omada gateways |
| Published | Aug 3, 2026 |
| Last Updated | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link systems inc. omada gateways
Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. omada gateways are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TP-Link Systems Inc. / Omada Gateways
0
TP-Link Systems Inc. / Omada Switches
0
TP Link Systems Inc. / Omada Access Points
0
TP-Link Systems Inc / Omada Controllers
0
References
Credits
Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies