Junglewise Threat Intelligence

CVE-2025-15630: TP-Link Omada cloud device adoption race condition

CVE-2025-15630 · Severity: medium · CVSS 5.9 · Published 2026-08-03

Technologies: TP-Link Deco BE65 Pro, TP-Link Deco BE25, TP-Link Deco BE65-PoE, TP-Link Deco BE65, TP-Link Deco BE85, TP-Link Deco BE23. Vendors: TP-Link.

Executive brief

TP-Link's Omada cloud platform handles the onboarding process for networking devices like mesh routers and access points. An attacker can exploit a timing vulnerability during device registration to intercept provisioning information intended for legitimate devices, potentially gaining unauthorized access to configuration details and network credentials.

Technical details

A race condition exists in the cloud-based Omada device adoption workflow that allows an attacker to interact with the registration process before a legitimate device completes enrollment. The vulnerability is triggered during the adoption phase when provisioning information is allocated but not yet tied to a specific authenticated device. An attacker can initiate the adoption workflow and receive the provisioning data meant for the legitimate device. The attack requires network access to the Omada cloud service and the ability to initiate device adoption requests, but does not require prior authentication or compromise of the target device.

Affected products

  • TP-Link Omada Cloud
  • TP-Link Deco BE85
  • TP-Link Deco BE65
  • TP-Link Deco BE65-PoE
  • TP-Link Deco BE65 Pro
  • TP-Link Deco BE25
  • TP-Link Deco BE23

Timeline

  • 2025-08-03: disclosed

References