CVE-2025-15627
Severity CVSS v4.0:
MEDIUM
Type:
CWE-321
Use of Hard-coded Cryptographic Key
Publication date:
03/08/2026
Last modified:
07/08/2026
Description
A cryptographic<br />
weakness exists in the Omada adoption protocol. <br />
The protocol relies on hard-coded cryptographic keys to establish trust and<br />
protect authentication exchanges between controllers and managed devices during<br />
device adoption.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
An attacker may<br />
be able to impersonate trusted controllers or managed devices and gain access<br />
to sensitive adoption-related communications.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tp-link:omada_oc200_v3_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_oc200_v3:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_oc300_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_oc300:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_oc400_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_oc400:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_fusion_2.5g_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_fusion_2.5g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er707-m2_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_er707-m2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_tl-sg3452x_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_tl-sg3452x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_sg3428xmpp_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_sg3428xmpp:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_sg3428xmp_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



