PT-2026-67460 · Tp Link · Omada

CVE-2025-15629

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TP-Link Omada (affected versions not specified)
Description A cryptographic weakness exists in the Omada adoption protocol. Session encryption keys used to protect communications between controllers and managed devices may be predictable because of insufficient entropy during session key generation. Entropy refers to the randomness collected for use in cryptographic operations. An attacker who intercepts adoption-related communications could recover these session encryption keys to decrypt the affected traffic.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15629

Affected Products

Omada