SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-15627

A cryptographic weakness exists in the Omada adoption protocol.

MEDIUM 6.9EPSS 0.35%

Does this matter?

Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.

Description

A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications.

CVSS 4.0
6.9 MEDIUMCVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.35% probability · 28th percentile
CISA KEV
Not listed
Weakness
CWE-321
Affected
tp-link/omada oc200 v3 firmware · tp-link/omada oc300 firmware · tp-link/omada oc400 firmware · tp-link/omada fusion 2.5g firmware · tp-link/omada er707-m2 firmware · tp-link/omada tl-sg3452x firmware · tp-link/omada sg3428xmpp firmware · tp-link/omada sg3428xmp firmware · tp-link/omada sg3428x firmware · tp-link/omada sg2005p-pd firmware · tp-link/omada sg3452p firmware · tp-link/omada sg3452 firmware · tp-link/omada sg3428mp firmware · tp-link/omada sg3428 firmware · tp-link/omada sg3210 firmware · tp-link/omada tl-sg3210 firmware · tp-link/omada sg2452lp firmware · tp-link/omada sg2428p firmware · tp-link/omada sg2428lp firmware · tp-link/omada sg2218p firmware · +40 more
Source
f23511db-6c3e-4e32-a477-6aa17d310630

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.