CVE-2025-15628
Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications.
Weakness
Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications.
Affected products
- tp-link omada_oc200_v3_firmware
- tp-link omada_oc200_v3
- tp-link omada_oc300_firmware
- tp-link omada_oc300
- tp-link omada_oc400_firmware
- tp-link omada_oc400
- tp-link omada_fusion_2.5g_firmware
- tp-link omada_fusion_2.5g
References
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.