CVE-2025-15544
A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
- EPSS probability
- 0.20%
- CWE
- CWE-759
- Published
- 2026-08-03
- Last modified
- 2026-08-03
Affected products
- TP-Link Systems Inc. Omada Gateways
- TP-Link Systems Inc. Omada Switches
- TP Link Systems Inc. Omada Access Points
- TP-Link Systems Inc. Omada App
- TP-Link Systems Inc Omada Controllers
- TP-Link Systems Inc Omada OLTs
Weakness type
Related vulnerabilities
- CVE-2026-6217 — Information Disclosure in Pik Online Software's Portal
- CVE-2025-36271 — IBM Integrated Analytics System (IIAS) is affected by a predictable salt vulnerability in Magneto component
- CVE-2026-57263 — A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password...
- CVE-2025-15631 — Weak Credential Storage in TP-Link Omada Devices
- CVE-2026-45787 — electerm's encrypt method not safe enough
- CVE-2026-45027 — WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php
- CVE-2026-9370 — ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
- CVE-2025-36253 — Multiple Vulnerabilities in IBM Concert Software.