CVE-2025-15544

Medium5.9Published on August 3, 2026

A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.

CVSS score5.9 / 10CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness type (CWE)CWE-759
Vendorstp-link

Affected products

VendorsProductVersions
tp-linkomada oc200 v3 firmware-
tp-linkomada oc200 v3-
tp-linkomada oc300 firmware-
tp-linkomada oc300-
tp-linkomada oc400 firmware-
tp-linkomada oc400-
tp-linkomada fusion 2.5g firmware-
tp-linkomada fusion 2.5g-
tp-linkomada er707-m2 firmware-
tp-linkomada er707-m2-
tp-linkomada er7206 firmware-
tp-linkomada er7206-
tp-linkomada er706w firmware-
tp-linkomada er706w-
tp-linkomada er8411 firmware-
tp-linkomada er8411-
tp-linkomada er605 firmware-
tp-linkomada er605-
tp-linkomada er7412-m2 firmware-
tp-linkomada er7412-m2-
tp-linkomada er706w-4g firmware-
tp-linkomada er706w-4g-
tp-linkomada er703wp-4g-outdoor firmware-
tp-linkomada er703wp-4g-outdoor-
tp-linkomada er706wp-4g firmware-

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database