← Vulnerability feed

Vulnerability record · CVE-2025-15544 · published 3 August 2026

CVE-2025-15544: Tp-link omada oc200 v3 firmware vulnerability

Tp Link · Omada Oc200 V3 Firmware

A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.

6.9 CVSS 4.0 Medium EPSS 0.34% · top 74.8% CWE-759 · CWE-759
6.9CVSS 4.0 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
113Affected product versions listed by NVD
3References
7 Aug 2026Last modified by NVD

Description

A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.

CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

113 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-15544 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2025-15628Tp-link omada oc200 v3 firmware hard-coded credentials vulnerabilityAffected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. A…EPSS 0.32%7.7CVE-2025-9291Tp-link omada fusion 2.5g firmware improper certificate validation vulnerabilityA certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification d…EPSS 0.22%7.7CVE-2025-9293Tp-link aginet improper certificate validation vulnerabilityA vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS c…EPSS 0.23%6.9CVE-2025-15627Tp-link omada oc200 v3 firmware vulnerabilityA cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect …EPSS 0.68%6.9CVE-2025-15629Tp-link omada oc200 v3 firmware vulnerabilityA cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and m…EPSS 0.33%5.8CVE-2025-15630Tp-link omada oc200 v3 firmware race condition vulnerabilityA race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a…EPSS 0.31%5.7CVE-2025-15631Tp-link omada fusion 2.5g firmware vulnerabilityA cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide…EPSS 0.30%2.0CVE-2025-9292Tp-link aginet vulnerabilityA permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. …EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2025-15544), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.