Skip to content
CodeAuditAgent

CVE-2025-15631

A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments.

Weakness

A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments.

Affected products

  • tp-link omada_fusion_2.5g_firmware
  • tp-link omada_fusion_2.5g
  • tp-link omada_er707-m2_firmware
  • tp-link omada_er707-m2
  • tp-link omada_er7206_firmware
  • tp-link omada_er7206
  • tp-link omada_er706w_firmware
  • tp-link omada_er706w

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.