A cryptographic
weakness exists in the Omada adoption protocol.
The protocol relies on hard-coded cryptographic keys to establish trust and
protect authentication exchanges between controllers and managed devices during
device adoption.
An attacker may
be able to impersonate trusted controllers or managed devices and gain access
to sensitive adoption-related communications.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link omada Controller Tp-link omada Gateways Tp-link omada Switches Tp Link Tp Link omada Access Points |
|
| Vendors & Products |
Tp-link
Tp-link omada Controller Tp-link omada Gateways Tp-link omada Switches Tp Link Tp Link omada Access Points |
Wed, 05 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications. | |
| Title | Hardcoded Cryptographic Keys in TP-Link Omada Adoption Protocol Authentication | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-08-03T18:33:55.632Z
Reserved: 2026-04-10T16:33:36.703Z
Link: CVE-2025-15627
Updated: 2026-08-03T18:33:51.488Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T10:21:50Z