{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-15631","assignerOrgId":"f23511db-6c3e-4e32-a477-6aa17d310630","state":"PUBLISHED","assignerShortName":"TPLink","dateReserved":"2026-04-10T16:33:57.776Z","datePublished":"2026-08-03T17:51:52.265Z","dateUpdated":"2026-08-03T18:29:33.225Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f23511db-6c3e-4e32-a477-6aa17d310630","shortName":"TPLink","dateUpdated":"2026-08-03T17:51:52.265Z"},"title":"Weak Credential Storage in TP-Link Omada Devices","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-759","description":"CWE-759 Use of a One-Way hash without a salt","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-55","descriptions":[{"lang":"en","value":"CAPEC-55 Rainbow Table Password Cracking"}]}],"affected":[{"vendor":"TP-Link Systems Inc.","product":"Omada Gateways","versions":[{"status":"affected","version":"0","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"Omada Switches","versions":[{"status":"affected","version":"0","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP Link Systems Inc.","product":"Omada Access Points","versions":[{"status":"affected","version":"0","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"Omada OLTs","versions":[{"status":"affected","version":"0","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"A\ncryptographic weakness exists in affected Omada devices where site credentials\nare protected using a legacy hashing algorithm that does not provide sufficient\nprotection.\n\n\n\n\n\n\n\n\n\nAn attacker\nwho obtains access to stored credential data may be able to recover valid credentials\nto gain unauthorized access to affected devices or management environments.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>A\ncryptographic weakness exists in affected Omada devices where site credentials\nare protected using a legacy hashing algorithm that does not provide sufficient\nprotection.</p><p>\n\n</p><p>An attacker\nwho obtains access to stored credential data may be able to recover valid credentials\nto gain unauthorized access to affected devices or management environments.</p>"}]}],"references":[{"url":"https://www.omadanetworks.com/us/support/download/","tags":["patch"]},{"url":"https://www.omadanetworks.com/en/support/download/","tags":["patch"]},{"url":"https://www.tp-link.com/us/support/faq/5216/","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":5.7,"vectorString":"CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}}],"credits":[{"lang":"en","value":"Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.4"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-03T18:29:21.933159Z","id":"CVE-2025-15631","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-03T18:29:33.225Z"}}]}}