Omada devices rely on embedded certificates that are shared across deployments
to establish trust between controllers and managed devices.
An attacker
who obtains the embedded certificates may be able to impersonate trusted
controllers or devices and intercept affected communications.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link omada Access Points Tp-link omada Controller Tp-link omada Gateways Tp-link omada Olts Tp-link omada Switches |
|
| Vendors & Products |
Tp-link
Tp-link omada Access Points Tp-link omada Controller Tp-link omada Gateways Tp-link omada Olts Tp-link omada Switches |
Mon, 03 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications. | |
| Title | Hardcoded Certificates in TP-Link Omada Device Communications | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-08-03T18:33:03.658Z
Reserved: 2026-04-10T16:33:49.709Z
Link: CVE-2025-15628
Updated: 2026-08-03T18:32:56.162Z
Status : Analyzed
Published: 2026-08-03T19:16:40.567
Modified: 2026-08-07T15:14:05.580
Link: CVE-2025-15628
No data.
OpenCVE Enrichment
Updated: 2026-08-05T10:21:48Z