Ir para o conteúdo
CodeAuditAgent

CVE-2025-15544

A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.

Fraqueza

A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments.

Produtos afetados

  • tp-link omada_oc200_v3_firmware
  • tp-link omada_oc200_v3
  • tp-link omada_oc300_firmware
  • tp-link omada_oc300
  • tp-link omada_oc400_firmware
  • tp-link omada_oc400
  • tp-link omada_fusion_2.5g_firmware
  • tp-link omada_fusion_2.5g

Referências

Encontre a falha antes de um atacante.

Entre com o GitHub e rode sua primeira auditoria em menos de um minuto. O plano gratuito não exige cartão de crédito.