PT-2026-67459 · Tp Link Systems · Omada Access Point+4

CVE-2025-15628

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v4.0

8.2

High

VectorAV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices.
An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15628

Affected Products

Omada Access Point
Omada Controller
Omada Gateways
Omada Olts
Omada Switches