VulnerabilityAnalyzed
CVE-2025-15628
An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications.
HIGH 8.2EPSS 0.22%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications.
- CVSS 4.0
- 8.2 HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.22% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- tp-link/omada oc200 v3 firmware · tp-link/omada oc300 firmware · tp-link/omada oc400 firmware · tp-link/omada fusion 2.5g firmware · tp-link/omada er707-m2 firmware · tp-link/omada tl-sg3452x firmware · tp-link/omada sg3428xmpp firmware · tp-link/omada sg3428xmp firmware · tp-link/omada sg3428x firmware · tp-link/omada sg2005p-pd firmware · tp-link/omada sg3452p firmware · tp-link/omada sg3452 firmware · tp-link/omada sg3428mp firmware · tp-link/omada sg3428 firmware · tp-link/omada sg3210 firmware · tp-link/omada tl-sg3210 firmware · tp-link/omada sg2452lp firmware · tp-link/omada sg2428p firmware · tp-link/omada sg2428lp firmware · tp-link/omada sg2218p firmware · +40 more
- Source
- f23511db-6c3e-4e32-a477-6aa17d310630
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.