HIGH · 7.5

CVE-2025-15629

A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficie...

Vulnerability Description

A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be able to recover session encryption keys and decrypt affected communications.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Tp-LinkOmada Oc200 V3 Firmware-
Tp-LinkOmada Oc200 V3-
Tp-LinkOmada Oc300 Firmware-
Tp-LinkOmada Oc300-
Tp-LinkOmada Oc400 Firmware-
Tp-LinkOmada Oc400-
Tp-LinkOmada Fusion 2.5G Firmware-
Tp-LinkOmada Fusion 2.5G-
Tp-LinkOmada Er707-M2 Firmware-
Tp-LinkOmada Er707-M2-
Tp-LinkOmada Er7206 Firmware-
Tp-LinkOmada Er7206-
Tp-LinkOmada Er706W Firmware-
Tp-LinkOmada Er706W-
Tp-LinkOmada Er8411 Firmware-
Tp-LinkOmada Er8411-
Tp-LinkOmada Er605 Firmware-
Tp-LinkOmada Er605-
Tp-LinkOmada Er7412-M2 Firmware-
Tp-LinkOmada Er7412-M2-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-15629?

CVE-2025-15629 is a vulnerability with a CVSS score of 7.5 (HIGH). A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficie...

How severe is CVE-2025-15629?

CVE-2025-15629 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-15629?

Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Omada Oc200 V3 Firmware, Tp-Link Omada Oc200 V3, Tp-Link Omada Oc300 Firmware, Tp-Link Omada Oc300, Tp-Link Omada Oc400 Firmware.