ZeroHour

CVE-2025-15627

CVSS 4.0
6.9 medium
EPSS
<1%p28
Published
()
Modified
Description

A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications.

Vendors
tp-link
Products
omada oc200 v3 firmware, omada oc300 firmware, omada oc400 firmware, omada fusion 2.5g firmware, omada er707-m2 firmware, omada tl-sg3452x firmware, omada sg3428xmpp firmware, omada sg3428xmp firmware, omada sg3428x firmware, omada sg2005p-pd firmware, omada sg3452p firmware, omada sg3452 firmware
Weakness
CWE-321
Vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.