CVE-2025-15631
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
03/08/2026
Last modified:
07/08/2026
Description
A<br />
cryptographic weakness exists in affected Omada devices where site credentials<br />
are protected using a legacy hashing algorithm that does not provide sufficient<br />
protection.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
An attacker<br />
who obtains access to stored credential data may be able to recover valid credentials<br />
to gain unauthorized access to affected devices or management environments.
Impact
Base Score 4.0
5.70
Severity 4.0
MEDIUM
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tp-link:omada_fusion_2.5g_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_fusion_2.5g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er707-m2_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_er707-m2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er7206_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_er7206:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er706w_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_er706w:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er8411_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_er8411:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er605_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_er605:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er7412-m2_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:omada_er7412-m2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:omada_er706w-4g_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



