{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-15629","assignerOrgId":"f23511db-6c3e-4e32-a477-6aa17d310630","state":"PUBLISHED","assignerShortName":"TPLink","dateReserved":"2026-04-10T16:33:52.786Z","datePublished":"2026-08-03T17:50:44.038Z","dateUpdated":"2026-08-03T18:32:11.317Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f23511db-6c3e-4e32-a477-6aa17d310630","shortName":"TPLink","dateUpdated":"2026-08-03T17:50:44.038Z"},"title":"Weak Session Key Generation in TP-Link Omada Adoption Protocol","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-331","description":"CWE-331 Insufficient entropy","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-20","descriptions":[{"lang":"en","value":"CAPEC-20 Encryption Brute Forcing"}]}],"affected":[{"vendor":"TP-Link Systems Inc.","product":"Omada Gateways","versions":[{"status":"affected","version":"0","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"Omada Switches","versions":[{"status":"affected","version":"0","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP Link Systems Inc.","product":"Omada Access Points","versions":[{"status":"affected","version":"0","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc","product":"Omada Controllers","versions":[{"status":"affected","version":"0","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"A cryptographic\nweakness exists in the Omada adoption protocol where session encryption keys\nused to protect communications between controllers and managed devices may be\npredictable due to insufficient entropy in session key generation.\n\n\n\n\n\n\n\n\n\nAn attacker\nwho successfully intercepts adoption-related communications may be able to recover\nsession encryption keys and decrypt affected communications.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>A cryptographic\nweakness exists in the Omada adoption protocol where session encryption keys\nused to protect communications between controllers and managed devices may be\npredictable due to insufficient entropy in session key generation.</p><p>\n\n</p><p>An attacker\nwho successfully intercepts adoption-related communications may be able to recover\nsession encryption keys and decrypt affected communications.</p>"}]}],"references":[{"url":"https://www.omadanetworks.com/us/support/download/","tags":["patch"]},{"url":"https://www.omadanetworks.com/en/support/download/","tags":["patch"]},{"url":"https://www.tp-link.com/us/support/faq/5216/","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":6.9,"vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"}}],"credits":[{"lang":"en","value":"Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.4"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-03T18:30:52.825327Z","id":"CVE-2025-15629","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-03T18:32:11.317Z"}}]}}