condition exists in the cloud-based Omada device adoption process when an
attacker may be able to interact with the adoption workflow before a legitimate
device completes registration, resulting in provisioning information being
delivered to an attacker.
Successful
exploitation may allow disclosure of provisioning information intended for a
legitimate device.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link omada Access Point Tp-link omada Controller Tp-link omada Gateways Tp-link omada Switches |
|
| Vendors & Products |
Tp-link
Tp-link omada Access Point Tp-link omada Controller Tp-link omada Gateways Tp-link omada Switches |
Wed, 05 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of provisioning information intended for a legitimate device. | |
| Title | Device Provisioning Race Condition in TP-Link Omada Adoption Workflow | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-08-03T18:30:42.253Z
Reserved: 2026-04-10T16:33:55.447Z
Link: CVE-2025-15630
Updated: 2026-08-03T18:30:38.824Z
Status : Analyzed
Published: 2026-08-03T19:16:40.880
Modified: 2026-08-07T15:13:46.860
Link: CVE-2025-15630
No data.
OpenCVE Enrichment
Updated: 2026-08-05T10:21:45Z