# CVE-2025-15544

## Summary

- **CVE ID:** CVE-2025-15544
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N)
- **CWE:** CWE-759
- **Published:** Aug 3, 2026
- **Last Modified:** Aug 3, 2026

## Description

A cryptographic
weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated
with site management are transmitted using a weak hashing algorithm that does
not provide sufficient protection. 









An attacker who
successfully intercepts adoption-related authentication traffic may be able to
recover valid credentials and gain unauthorized access to managed devices or
controller-managed environments.

## Affected Products

- TP-Link Systems Inc. — Omada Gateways (0)
- TP-Link Systems Inc. — Omada Switches (0)
- TP Link Systems Inc. — Omada Access Points (0)
- TP-Link Systems Inc. — Omada App (0)
- TP-Link Systems Inc — Omada Controllers (0)
- TP-Link Systems Inc — Omada OLTs (0)

## References

- [CNA](https://www.omadanetworks.com/us/support/download/)
- [CNA](https://www.omadanetworks.com/en/support/download/)
- [CNA](https://www.tp-link.com/us/support/faq/5216/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 10.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._