CVE-2025-15631: Weak Credential Storage in TP-Link Omada Devices
A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection.
An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15631?
CVE-2025-15631 has a risk rating of 47, indicating a significant security concern.
How do I fix CVE-2025-15631?
To fix CVE-2025-15631, update your TP-Link Omada devices to the latest firmware version provided by the manufacturer.
What devices are affected by CVE-2025-15631?
CVE-2025-15631 affects various TP-Link Omada devices that utilize weak credential storage.
What are the potential consequences of CVE-2025-15631?
Exploitation of CVE-2025-15631 could allow attackers to recover valid credentials and gain unauthorized access to the affected TP-Link Omada devices.
Is there a workaround for CVE-2025-15631?
Currently, the best workaround for CVE-2025-15631 is to implement strong access control measures while awaiting a firmware update.