Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-15544 | 2 Tp-link, Tp Link | 231 Omada, Omada App, Omada Controller and 228 more | 2026-08-05 | 5.9 Medium |
| A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments. | ||||
| CVE-2025-15627 | 2 Tp-link, Tp Link | 228 Omada Controller, Omada Ds1008x, Omada Ds1008x Firmware and 225 more | 2026-08-05 | 7.5 High |
| A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications. | ||||
| CVE-2025-15628 | 1 Tp-link | 229 Omada Access Points, Omada Controller, Omada Ds1008x and 226 more | 2026-08-05 | 7.5 High |
| Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications. | ||||
Page 1 of 1.