{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-15627","assignerOrgId":"f23511db-6c3e-4e32-a477-6aa17d310630","state":"PUBLISHED","assignerShortName":"TPLink","dateReserved":"2026-04-10T16:33:36.703Z","datePublished":"2026-08-03T17:49:46.749Z","dateUpdated":"2026-08-03T18:33:55.632Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f23511db-6c3e-4e32-a477-6aa17d310630","shortName":"TPLink","dateUpdated":"2026-08-03T17:49:46.749Z"},"title":"Hardcoded Cryptographic Keys in TP-Link Omada Adoption Protocol Authentication","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-321","description":"CWE-321 Use of hard-coded cryptographic key","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-115","descriptions":[{"lang":"en","value":"CAPEC-115 Authentication Bypass"}]}],"affected":[{"vendor":"TP-Link Systems Inc.","product":"Omada Gateways","versions":[{"status":"affected","version":"0","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"Omada Switches","versions":[{"status":"affected","version":"0","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP Link Systems Inc.","product":"Omada Access Points","versions":[{"status":"affected","version":"0","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc","product":"Omada Controllers","versions":[{"status":"affected","version":"0","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"A cryptographic\nweakness exists in the Omada adoption protocol. \nThe protocol relies on hard-coded cryptographic keys to establish trust and\nprotect authentication exchanges between controllers and managed devices during\ndevice adoption.\n\n\n\n\n\n\n\n\n\nAn attacker may\nbe able to impersonate trusted controllers or managed devices and gain access\nto sensitive adoption-related communications.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>A cryptographic\nweakness exists in the Omada adoption protocol.&nbsp;\nThe protocol relies on hard-coded cryptographic keys to establish trust and\nprotect authentication exchanges between controllers and managed devices during\ndevice adoption.</p><p>\n\n</p><p>An attacker may\nbe able to impersonate trusted controllers or managed devices and gain access\nto sensitive adoption-related communications.</p>"}]}],"references":[{"url":"https://www.omadanetworks.com/us/support/download/","tags":["patch"]},{"url":"https://www.omadanetworks.com/en/support/download/","tags":["patch"]},{"url":"https://www.tp-link.com/us/support/faq/5216/","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":6.9,"vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"}}],"credits":[{"lang":"en","value":"Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.4"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-03T18:33:46.235394Z","id":"CVE-2025-15627","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-03T18:33:55.632Z"}}]}}