Junglewise Threat Intelligence

CVE-2025-15544: TP-Link Omada device adoption cryptographic weakness

CVE-2025-15544 · Severity: medium · CVSS 5.9 · Published 2026-08-03

Technologies: TP-Link Omada. Vendors: TP-Link.

Executive brief

TP-Link's Omada network management system uses a weak hashing algorithm during device adoption to protect site management credentials. An attacker who intercepts adoption traffic can recover valid credentials and gain unauthorized access to managed network devices or the central controller.

Technical details

This vulnerability stems from the use of an insufficiently strong hashing algorithm to protect authentication credentials transmitted during the Omada device adoption process. The weak cryptographic implementation fails to provide adequate security for site management credentials. An attacker positioned to intercept network traffic during device adoption (network-level access required) can recover valid credentials and use them to gain unauthorized access to Omada-managed devices or the controller. No user interaction is required beyond normal device adoption procedures. Patches addressing this cryptographic weakness are likely available from TP-Link.

Affected products

  • TP-Link Omada <UNKNOWN>

Timeline

  • 2026-08-03: disclosed

References

Related threats