CVE-2025-15544
Received Received - Intake

Weak Hashing in Omada Controller Adoption Process

Vulnerability report for CVE-2025-15544, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: TPLink

Description

A cryptographic weakness exists in the Omada device adoption process.Β  During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-04
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-759 The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cryptographic weakness in the Omada device adoption process. During adoption, authentication credentials for site management are transmitted using a weak hashing algorithm that fails to provide adequate protection. An attacker who intercepts this traffic could recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.

Detection Guidance

This vulnerability involves weak hashing of credentials during Omada device adoption. Detection requires monitoring network traffic for adoption-related authentication exchanges. Use packet capture tools like tcpdump or Wireshark to inspect adoption traffic for weak hash algorithms or plaintext credential transmission. Look for unencrypted or weakly encrypted credential exchanges during device adoption processes.

Impact Analysis

If exploited, this vulnerability could allow attackers to gain unauthorized access to your Omada devices or the entire managed environment. This may lead to data breaches, unauthorized configuration changes, or disruption of services relying on these devices.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other regulations due to unauthorized access risks. It may result in data breaches, loss of sensitive information, and failure to meet security requirements for protecting personal or health data.

Mitigation Strategies

Immediately update Omada devices and controller software to the latest patched versions to address the weak hashing algorithm in the adoption process. Disable adoption over untrusted networks and use secure, encrypted channels for all authentication traffic.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15544. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart