HIGH · 7.5

CVE-2025-15627

A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and ma...

Vulnerability Description

A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Tp-LinkOmada Oc200 V3 Firmware-
Tp-LinkOmada Oc200 V3-
Tp-LinkOmada Oc300 Firmware-
Tp-LinkOmada Oc300-
Tp-LinkOmada Oc400 Firmware-
Tp-LinkOmada Oc400-
Tp-LinkOmada Fusion 2.5G Firmware-
Tp-LinkOmada Fusion 2.5G-
Tp-LinkOmada Er707-M2 Firmware-
Tp-LinkOmada Er707-M2-
Tp-LinkOmada Tl-Sg3452X Firmware-
Tp-LinkOmada Tl-Sg3452X-
Tp-LinkOmada Sg3428Xmpp Firmware-
Tp-LinkOmada Sg3428Xmpp-
Tp-LinkOmada Sg3428Xmp Firmware-
Tp-LinkOmada Sg3428Xmp-
Tp-LinkOmada Sg3428X Firmware-
Tp-LinkOmada Sg3428X-
Tp-LinkOmada Sg2005P-Pd Firmware-
Tp-LinkOmada Sg2005P-Pd-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-15627?

CVE-2025-15627 is a vulnerability with a CVSS score of 7.5 (HIGH). A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and ma...

How severe is CVE-2025-15627?

CVE-2025-15627 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-15627?

Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Omada Oc200 V3 Firmware, Tp-Link Omada Oc200 V3, Tp-Link Omada Oc300 Firmware, Tp-Link Omada Oc300, Tp-Link Omada Oc400 Firmware.