CVE-2025-15544: Weak Credential Protection During TP-Link Omada Device Adoption
A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection.
An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15544?
The severity of CVE-2025-15544 is rated at 55, indicating a moderate risk level.
How do I fix CVE-2025-15544?
To fix CVE-2025-15544, update your TP-Link Omada devices to the latest firmware that addresses the cryptographic weakness.
What systems are affected by CVE-2025-15544?
CVE-2025-15544 affects TP-Link Omada devices involved in the adoption process.
What type of vulnerability is CVE-2025-15544?
CVE-2025-15544 is classified as a cryptographic weakness that compromises credential protection.
How does CVE-2025-15544 impact device security?
CVE-2025-15544 can allow attackers to intercept weakly hashed authentication credentials during the device adoption process.