CVE-2025-15627
Received Received - Intake

Hard-Coded Cryptographic Keys in Omada Adoption Protocol

Vulnerability report for CVE-2025-15627, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: TPLink

Description

A cryptographic weakness exists in the Omada adoption protocol.Β  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-04
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cryptographic weakness in the Omada adoption protocol. It uses hard-coded cryptographic keys to establish trust between controllers and managed devices during device adoption. Attackers can exploit this to impersonate trusted controllers or devices and gain access to sensitive adoption communications.

Detection Guidance

This vulnerability involves weak cryptographic keys in the Omada adoption protocol. Detection requires inspecting network traffic for hard-coded keys or unusual adoption exchanges. Use packet capture tools like tcpdump or Wireshark to analyze Omada protocol traffic between controllers and devices. Look for repeated or predictable key exchanges.

Impact Analysis

An attacker could intercept or manipulate adoption-related communications, potentially gaining unauthorized access to your network or sensitive data. This could lead to unauthorized device control or exposure of confidential information.

Compliance Impact

This vulnerability may violate compliance requirements for data protection and network security, such as GDPR or HIPAA, by enabling unauthorized access to sensitive communications. Organizations could face penalties for failing to protect data integrity and confidentiality.

Mitigation Strategies

Immediately update Omada controller and managed devices to the latest patched versions to remove hard-coded cryptographic keys and enforce secure adoption protocols.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15627. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart