PT-2026-67458 · Tp Link Systems · Omada Access Point+3

CVE-2025-15627

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v4.0

6.9

Medium

VectorAV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption.
An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15627

Affected Products

Omada Access Point
Omada Controller
Omada Gateways
Omada Switches