CVE-2025-15628
Received Received - Intake

Authentication Bypass in Omada Devices via Embedded Certificates

Vulnerability report for CVE-2025-15628, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: TPLink

Description

Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-04
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Omada devices using shared embedded certificates across deployments to establish trust between controllers and managed devices. If an attacker obtains these certificates, they can impersonate trusted controllers or devices and intercept communications.

Detection Guidance

Detection involves checking for unauthorized or unexpected Omada controller or device communications. Monitor network traffic for unusual TLS handshakes or certificate exchanges. Inspect Omada controller logs for anomalies in device authentication. Use network scanning tools to identify Omada devices and verify their certificates are not shared or compromised.

Impact Analysis

An attacker could intercept sensitive communications between Omada devices, potentially gaining unauthorized access to data or disrupting network operations. This could lead to data breaches or unauthorized control of networked devices.

Compliance Impact

This vulnerability could lead to unauthorized access or interception of sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Immediately rotate all embedded certificates on Omada controllers and managed devices. Ensure new certificates are unique per deployment. Update Omada software to the latest version if a patch is available. Restrict network access to Omada controllers and devices to trusted IPs only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15628. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart