CVE-2025-15627

High7.5Published on August 3, 2026

A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications.

CVSS score7.5 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness type (CWE)CWE-321
Vendorstp-link

Affected products

VendorsProductVersions
tp-linkomada oc200 v3 firmware-
tp-linkomada oc200 v3-
tp-linkomada oc300 firmware-
tp-linkomada oc300-
tp-linkomada oc400 firmware-
tp-linkomada oc400-
tp-linkomada fusion 2.5g firmware-
tp-linkomada fusion 2.5g-
tp-linkomada er707-m2 firmware-
tp-linkomada er707-m2-
tp-linkomada tl-sg3452x firmware-
tp-linkomada tl-sg3452x-
tp-linkomada sg3428xmpp firmware-
tp-linkomada sg3428xmpp-
tp-linkomada sg3428xmp firmware-
tp-linkomada sg3428xmp-
tp-linkomada sg3428x firmware-
tp-linkomada sg3428x-
tp-linkomada sg2005p-pd firmware-
tp-linkomada sg2005p-pd-
tp-linkomada sg3452p firmware-
tp-linkomada sg3452p-
tp-linkomada sg3452 firmware-
tp-linkomada sg3452-
tp-linkomada sg3428mp firmware-

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database