CVE-2025-15630
Received Received - Intake

Race Condition in Omada Device Adoption Process

Vulnerability report for CVE-2025-15630, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: TPLink

Description

A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of provisioning information intended for a legitimate device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-04
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
omada device_adoption *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-362 The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a race condition in the cloud-based Omada device adoption process. An attacker could exploit it by interacting with the adoption workflow before a legitimate device completes registration. This may cause provisioning information intended for the legitimate device to be sent to the attacker instead.

Detection Guidance

Detection methods are not specified in the provided CVE details. Monitor Omada device adoption logs for unusual activity or unauthorized provisioning attempts during the registration process.

Impact Analysis

Successful exploitation may lead to unauthorized disclosure of provisioning information. This could allow attackers to gain access to sensitive configuration details meant for legitimate devices, potentially compromising network security or enabling further attacks.

Compliance Impact

The vulnerability may lead to unauthorized disclosure of provisioning information, which could include sensitive data. This could potentially violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data privacy) if such data is exposed.

Mitigation Strategies

Implement strict access controls for the Omada device adoption process. Ensure only authorized devices can complete registration and provisioning. Monitor network traffic for suspicious interactions during adoption workflows.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15630. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart