Junglewise Threat Intelligence

CVE-2025-15628: TP-Link Omada devices shared embedded certificate impersonation

CVE-2025-15628 · Severity: high · CVSS 7.5 · Published 2026-08-03

Technologies: TP-Link Omada. Vendors: TP-Link.

Executive brief

TP-Link Omada is a network management system that controls and monitors WiFi access points and network devices across corporate and institutional deployments. The system uses embedded certificates shared across all devices to establish secure communication. An attacker who obtains these certificates can impersonate legitimate controllers or devices, intercept sensitive traffic, and potentially compromise the entire managed network.

Technical details

The vulnerability stems from the use of hardcoded, globally-shared embedded certificates across all Omada device deployments to establish trust relationships between controllers and managed devices. An attacker who obtains these certificates (through reverse engineering, firmware extraction, or disclosure) can cryptographically impersonate trusted devices or controllers without authentication. This allows man-in-the-middle attacks to intercept device-to-controller communications, potentially enabling credential theft, configuration changes, or lateral movement within managed networks. The vulnerability requires network access to the Omada network but no user interaction or authentication. Patch or fix availability has not been specified in available documentation.

Affected products

  • TP-Link Omada <UNKNOWN>

Timeline

  • 2026-08-03: disclosed: Published on NVD

References