# CVE-2025-15631

## Summary

- **CVE ID:** CVE-2025-15631
- **Severity:** MEDIUM
- **CVSS Score:** 5.7 (CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-759
- **Published:** Aug 3, 2026
- **Last Modified:** Aug 3, 2026

## Description

A
cryptographic weakness exists in affected Omada devices where site credentials
are protected using a legacy hashing algorithm that does not provide sufficient
protection.









An attacker
who obtains access to stored credential data may be able to recover valid credentials
to gain unauthorized access to affected devices or management environments.

## Affected Products

- TP-Link Systems Inc. — Omada Gateways (0)
- TP-Link Systems Inc. — Omada Switches (0)
- TP Link Systems Inc. — Omada Access Points (0)
- TP-Link Systems Inc. — Omada OLTs (0)

## References

- [CNA](https://www.omadanetworks.com/us/support/download/)
- [CNA](https://www.omadanetworks.com/en/support/download/)
- [CNA](https://www.tp-link.com/us/support/faq/5216/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.18%
- **EPSS Percentile:** 7.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._