CVE-2025-15630: Device Provisioning Race Condition in TP-Link Omada Adoption Workflow
A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker.
Successful exploitation may allow disclosure of provisioning information intended for a legitimate device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15630?
CVE-2025-15630 has a risk score of 33, indicating a moderate severity level.
How does CVE-2025-15630 affect TP-Link Omada devices?
CVE-2025-15630 allows an attacker to exploit a race condition during the device adoption workflow, potentially obtaining provisioning information.
What are the implications of exploiting CVE-2025-15630?
Successful exploitation of CVE-2025-15630 may allow attackers to control or manipulate device provisioning processes.
How do I fix CVE-2025-15630 on TP-Link Omada devices?
Mitigation for CVE-2025-15630 can typically be achieved by applying the latest firmware updates from TP-Link.
When was CVE-2025-15630 published?
CVE-2025-15630 was published on August 3, 2026.