CVE-2025-15628
Analyzed Analyzed - Analysis Complete

Authentication Bypass in Omada Devices via Embedded Certificates

Vulnerability report for CVE-2025-15628, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-07

Assigner: TPLink

Description

Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-07
Generated
2026-08-24
AI Q&A
2026-08-03
EPSS Evaluated
2026-08-22
NVD
EUVD

Affected Vendors & Products

Showing 112 associated CPEs
Vendor Product Version / Range
tp-link omada_oc200_v3_firmware *
tp-link omada_oc300_firmware *
tp-link omada_oc400_firmware *
tp-link omada_fusion_2.5g_firmware *
tp-link omada_er707-m2_firmware *
tp-link omada_tl-sg3452x_firmware *
tp-link omada_sg3428xmpp_firmware *
tp-link omada_sg3428xmp_firmware *
tp-link omada_sg3428x_firmware *
tp-link omada_sg2005p-pd_firmware *
tp-link omada_sg3452p_firmware *
tp-link omada_sg3452_firmware *
tp-link omada_sg3428mp_firmware *
tp-link omada_sg3428_firmware *
tp-link omada_sg3210_firmware *
tp-link omada_tl-sg3210_firmware *
tp-link omada_sg2452lp_firmware *
tp-link omada_sg2428p_firmware *
tp-link omada_sg2428lp_firmware *
tp-link omada_sg2218p_firmware *
tp-link omada_sg2218_firmware *
tp-link omada_sg2016p_firmware *
tp-link omada_sg2210mp_firmware *
tp-link omada_sg2210p_firmware *
tp-link omada_sg2008p_firmware *
tp-link omada_sg2008_firmware *
tp-link omada_sg2206mp_firmware *
tp-link omada_es210xpp-m2_firmware *
tp-link omada_es210x-m2_firmware *
tp-link omada_es206xpp-m2_firmware *
tp-link omada_es206x-m2_firmware *
tp-link omada_es228gmp_firmware *
tp-link omada_es228gp_firmware *
tp-link omada_es224g_firmware *
tp-link omada_es220gp_firmware *
tp-link omada_es216g_firmware *
tp-link omada_es210gmp_firmware *
tp-link omada_es210gp_firmware *
tp-link omada_es208gp_firmware *
tp-link omada_es208g_firmware *
tp-link omada_es206gp_firmware *
tp-link omada_es205gp_firmware *
tp-link omada_es205g_firmware *
tp-link omada_es220gmp_firmware *
tp-link omada_es1024ge_firmware *
tp-link omada_er7206_firmware *
tp-link omada_er706w_firmware *
tp-link omada_er8411_firmware *
tp-link omada_er605_firmware *
tp-link omada_er7412-m2_firmware *
tp-link omada_er706w-4g_firmware *
tp-link omada_er703wp-4g-outdoor_firmware *
tp-link omada_er706wp-4g_firmware *
tp-link omada_s7500-24y4c_firmware *
tp-link omada_s7500-26xf6y_firmware *
tp-link omada_s6500-48mpp6y_firmware *
tp-link omada_s6500-24mpp4y_firmware *
tp-link omada_s6500-48gp6xf_firmware *
tp-link omada_s6500-48g6xf_firmware *
tp-link omada_s6500-24gp4xf_firmware *
tp-link omada_s6500-24g4xf_firmware *
tp-link omada_sx6632yf_firmware *
tp-link omada_sx3032f_firmware *
tp-link omada_sx3016f_firmware *
tp-link omada_sx3008f_firmware *
tp-link omada_sg3428xf_firmware *
tp-link omada_sx3832mpp_firmware *
tp-link omada_sx3832_firmware *
tp-link omada_sx3206hpp_firmware *
tp-link omada_sg3428xpp-m2_firmware *
tp-link omada_sg3428x-m2_firmware *
tp-link omada_sg3218xp-m2_firmware *
tp-link omada_sg3210xhp-m2_firmware *
tp-link omada_sg3210x-m2_firmware *
tp-link omada_sg2210xmp-m2_firmware *
tp-link omada_sg6654xhp_firmware *
tp-link omada_sg6654x_firmware *
tp-link omada_sg6428xhp_firmware *
tp-link omada_sg6428x_firmware *
tp-link omada_sg5452xmpp_firmware *
tp-link omada_sg5452x_firmware *
tp-link omada_sg5428xmpp_firmware *
tp-link omada_sg5428x_firmware *
tp-link omada_sg3452xmpp_firmware *
tp-link omada_sg3452xp_firmware *
tp-link omada_ds1016ge_firmware *
tp-link omada_ds108ge_firmware *
tp-link omada_ds105ge_firmware *
tp-link omada_ds1008x_firmware *
tp-link omada_ds105x_firmware *
tp-link omada_ds108g-m2_firmware *
tp-link omada_ds105g-m2_firmware *
tp-link omada_ds1024g_firmware *
tp-link omada_ds1016g_firmware *
tp-link omada_ds110gmp_firmware *
tp-link omada_ds108g_firmware *
tp-link omada_ds106gpp_firmware *
tp-link omada_ds106p_firmware *
tp-link omada_ds105g_firmware *
tp-link omada_ds111p_firmware *
tp-link omada_ds1018gmp_firmware *
tp-link omada_ds108gp_firmware *
tp-link omada_ds105gp_firmware *
tp-link omada_ies210gpp_firmware *
tp-link omada_ies206gpp_firmware *
tp-link omada_ies208g_firmware *
tp-link omada_ies206g_firmware *
tp-link omada_eap660hd_firmware *
tp-link omada_eap620hd_firmware *
tp-link omada_eap610_firmware *
tp-link omada_eap615-wall_firmware *
tp-link omada_eap610-outdoor_firmware *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Omada devices using shared embedded certificates across deployments to establish trust between controllers and managed devices. If an attacker obtains these certificates, they can impersonate trusted controllers or devices and intercept communications.

Detection Guidance

Detection involves checking for unauthorized or unexpected Omada controller or device communications. Monitor network traffic for unusual TLS handshakes or certificate exchanges. Inspect Omada controller logs for anomalies in device authentication. Use network scanning tools to identify Omada devices and verify their certificates are not shared or compromised.

Impact Analysis

An attacker could intercept sensitive communications between Omada devices, potentially gaining unauthorized access to data or disrupting network operations. This could lead to data breaches or unauthorized control of networked devices.

Compliance Impact

This vulnerability could lead to unauthorized access or interception of sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Immediately rotate all embedded certificates on Omada controllers and managed devices. Ensure new certificates are unique per deployment. Update Omada software to the latest version if a patch is available. Restrict network access to Omada controllers and devices to trusted IPs only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15628. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart