CVE-2025-15631
Received Received - Intake

Weak Password Hashing in Omada Devices

Vulnerability report for CVE-2025-15631, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: TPLink

Description

A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-04
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
omada devices *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-759 The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cryptographic weakness in Omada devices where site credentials are protected using an outdated hashing algorithm. This makes it easier for attackers to recover valid credentials if they gain access to stored credential data, potentially allowing unauthorized access to devices or management environments.

Detection Guidance

This vulnerability involves weak cryptographic hashing of site credentials on Omada devices. Detection requires checking stored credential files or configurations for the use of legacy hashing algorithms. Review device logs and configuration files for signs of exposed or weakly hashed credentials. No specific commands are provided in the available context.

Impact Analysis

If exploited, an attacker could recover your credentials and gain unauthorized access to your Omada devices or management systems. This could lead to data breaches, loss of control over network devices, or further attacks on connected systems.

Compliance Impact

The vulnerability may lead to unauthorized access to stored credentials, potentially exposing sensitive data. This could violate compliance requirements under GDPR and HIPAA, which mandate strong protection of personal and health information.

Mitigation Strategies

Immediately update Omada devices to the latest firmware version to replace the weak hashing algorithm with a stronger one. Review stored credentials for any signs of compromise and rotate all passwords for affected devices and management environments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15631. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart