CVE-2025-15627
Une faiblesse cryptographique existe dans le protocole d'adoption Omada. Le protocole repose sur des clés cryptographiques codées en dur pour établir la confiance et protéger les échanges d'authentification entre les contrôleurs et les appareils gérés lors de l'adoption des appareils. Un attaquant peut être en mesure de se faire passer pour des contrôleurs ou des appareils gérés de confiance et d'accéder aux communications sensibles liées à l'adoption.
Score CVSS7.5 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NType de faiblesse (CWE)CWE-321
Éditeurstp-link
Produits concernés
| Éditeurs | Produit | Versions |
|---|---|---|
| tp-link | omada oc200 v3 firmware | - |
| tp-link | omada oc200 v3 | - |
| tp-link | omada oc300 firmware | - |
| tp-link | omada oc300 | - |
| tp-link | omada oc400 firmware | - |
| tp-link | omada oc400 | - |
| tp-link | omada fusion 2.5g firmware | - |
| tp-link | omada fusion 2.5g | - |
| tp-link | omada er707-m2 firmware | - |
| tp-link | omada er707-m2 | - |
| tp-link | omada tl-sg3452x firmware | - |
| tp-link | omada tl-sg3452x | - |
| tp-link | omada sg3428xmpp firmware | - |
| tp-link | omada sg3428xmpp | - |
| tp-link | omada sg3428xmp firmware | - |
| tp-link | omada sg3428xmp | - |
| tp-link | omada sg3428x firmware | - |
| tp-link | omada sg3428x | - |
| tp-link | omada sg2005p-pd firmware | - |
| tp-link | omada sg2005p-pd | - |
| tp-link | omada sg3452p firmware | - |
| tp-link | omada sg3452p | - |
| tp-link | omada sg3452 firmware | - |
| tp-link | omada sg3452 | - |
| tp-link | omada sg3428mp firmware | - |
Articles liés
This product uses the NVD API but is not endorsed or certified by the NVD.
La description technique est notre traduction du texte original du NVD, en anglais.
