CVE-2025-15631
A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.7
- CVSS vector
- CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.18%
- CWE
- CWE-759
- Published
- 2026-08-03
- Last modified
- 2026-08-03
Affected products
- TP-Link Systems Inc. Omada Gateways
- TP-Link Systems Inc. Omada Switches
- TP Link Systems Inc. Omada Access Points
- TP-Link Systems Inc. Omada OLTs
Weakness type
Related vulnerabilities
- CVE-2026-6217 — Information Disclosure in Pik Online Software's Portal
- CVE-2025-36271 — IBM Integrated Analytics System (IIAS) is affected by a predictable salt vulnerability in Magneto component
- CVE-2026-57263 — A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password...
- CVE-2025-15544 — Weak Credential Protection During TP-Link Omada Device Adoption
- CVE-2026-45787 — electerm's encrypt method not safe enough
- CVE-2026-45027 — WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php
- CVE-2026-9370 — ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
- CVE-2025-36253 — Multiple Vulnerabilities in IBM Concert Software.