CVE-2025-15629
Received Received - Intake

Predictable Session Key Generation in Omada Controller

Vulnerability report for CVE-2025-15629, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: TPLink

Description

A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be able to recover session encryption keys and decrypt affected communications.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-04
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
omada adoption_protocol *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-331 The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cryptographic weakness in the Omada adoption protocol where session encryption keys are predictable due to insufficient entropy during generation. Attackers intercepting adoption communications could recover these keys and decrypt the traffic.

Detection Guidance

Detection requires monitoring for predictable session key generation in Omada adoption protocol communications. Inspect network traffic for unencrypted or weakly encrypted adoption handshakes between controllers and devices. Use packet capture tools like tcpdump or Wireshark to analyze key exchange processes for entropy issues.

Impact Analysis

An attacker could decrypt sensitive communications between Omada controllers and managed devices, potentially exposing confidential data like network configurations or credentials.

Compliance Impact

This vulnerability may lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA, potentially resulting in compliance breaches and legal penalties.

Mitigation Strategies

Update Omada software to the latest version to ensure session key generation uses sufficient entropy. Monitor network traffic for unusual adoption protocol communications and restrict access to adoption ports between controllers and devices.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15629. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart