Junglewise Threat Intelligence

CVE-2025-15631: TP-Link Omada cryptographic weakness in credential hashing

CVE-2025-15631 · Severity: medium · CVSS 5.9 · Published 2026-08-03

Technologies: TP-Link Omada. Vendors: TP-Link.

Executive brief

TP-Link Omada networking devices use a weak hashing algorithm to protect administrator and site credentials stored in the device or management environment. An attacker who gains access to the stored credential hashes (through device compromise, database theft, or backup extraction) can crack them offline to recover plaintext credentials, leading to unauthorized administrative access and compromise of the entire network.

Technical details

This vulnerability stems from the use of a legacy or insufficient cryptographic hashing algorithm for protecting site credentials in Omada devices and their management systems. Rather than using modern password hashing schemes (e.g., bcrypt, scrypt, Argon2), the implementation allows attackers to brute-force or rainbow-table attack stored credential hashes with modest computational effort. The attack requires prior access to the credential storage—either through device filesystem access, database exfiltration, or backup file theft—but does not require authentication to the device or network access. Once credentials are recovered, an attacker gains full administrative control of affected Omada infrastructure.

Affected products

  • TP-Link Omada <UNKNOWN>
  • TP-Link Deco <UNKNOWN>

Timeline

  • 2026-08-03: disclosed

References