Junglewise Threat Intelligence

CVE-2025-15629: TP-Link Omada adoption protocol cryptographic weakness

CVE-2025-15629 · Severity: high · CVSS 7.5 · Published 2026-08-03

Technologies: TP-Link Deco BE65, TP-Link Deco BE23, TP-Link Deco BE65 Pro, TP-Link Deco BE65-PoE, TP-Link Deco BE25, TP-Link Deco BE85. Vendors: TP-Link.

Executive brief

TP-Link Omada is a network management platform used to control and monitor mesh WiFi devices and network infrastructure. A weakness in the adoption protocol allows attackers to predict encryption keys used to protect communications between controllers and managed devices. An attacker intercepting adoption traffic could decrypt sensitive communications, potentially gaining unauthorized access to network configuration or device management functions.

Technical details

The vulnerability is a cryptographic weakness in the Omada adoption protocol caused by insufficient entropy in session key generation. Session encryption keys used to protect communications between controllers and managed devices are predictable, allowing an attacker with network access to recover them. The attack requires an attacker to intercept adoption-related communications, then exploit the weak key generation to decrypt the traffic. Successful exploitation could lead to compromise of device management communications, potentially allowing unauthorized device takeover or network configuration changes. A patch or firmware update is likely needed to strengthen the key generation mechanism.

Affected products

  • TP-Link Deco BE85 multiple versions
  • TP-Link Deco BE65 multiple versions
  • TP-Link Deco BE65 Pro multiple versions
  • TP-Link Deco BE65-PoE multiple versions
  • TP-Link Deco BE25 multiple versions
  • TP-Link Deco BE23 multiple versions

Timeline

  • 2026-08-03: disclosed

References