CVE-2025-15627

HIGHCVSS 7.5/10EPSS 0.21%

Last modified

CVE-2025-15627 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS 4.0
6.9/10

CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.21%

11.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Tp-LinkOmada Oc200 V3 FirmwareAll versions
Tp-LinkOmada Oc300 FirmwareAll versions
Tp-LinkOmada Oc400 FirmwareAll versions
Tp-LinkOmada Fusion 2.5g FirmwareAll versions
Tp-LinkOmada Er707-M2 FirmwareAll versions
Tp-LinkOmada Tl-Sg3452x FirmwareAll versions
Tp-LinkOmada Sg3428xmpp FirmwareAll versions
Tp-LinkOmada Sg3428xmp FirmwareAll versions
Tp-LinkOmada Sg3428x FirmwareAll versions
Tp-LinkOmada Sg2005p-Pd FirmwareAll versions
Tp-LinkOmada Sg3452p FirmwareAll versions
Tp-LinkOmada Sg3452 FirmwareAll versions
Tp-LinkOmada Sg3428mp FirmwareAll versions
Tp-LinkOmada Sg3428 FirmwareAll versions
Tp-LinkOmada Sg3210 FirmwareAll versions
Tp-LinkOmada Tl-Sg3210 FirmwareAll versions
Tp-LinkOmada Sg2452lp FirmwareAll versions
Tp-LinkOmada Sg2428p FirmwareAll versions
Tp-LinkOmada Sg2428lp FirmwareAll versions
Tp-LinkOmada Sg2218p FirmwareAll versions
Tp-LinkOmada Sg2218 FirmwareAll versions
Tp-LinkOmada Sg2016p FirmwareAll versions
Tp-LinkOmada Sg2210mp FirmwareAll versions
Tp-LinkOmada Sg2210p FirmwareAll versions
Tp-LinkOmada Sg2008p FirmwareAll versions
Tp-LinkOmada Sg2008 FirmwareAll versions
Tp-LinkOmada Sg2206mp FirmwareAll versions
Tp-LinkOmada Es210xpp-M2 FirmwareAll versions
Tp-LinkOmada Es210x-M2 FirmwareAll versions
Tp-LinkOmada Es206xpp-M2 FirmwareAll versions
Tp-LinkOmada Es206x-M2 FirmwareAll versions
Tp-LinkOmada Es228gmp FirmwareAll versions
Tp-LinkOmada Es228gp FirmwareAll versions
Tp-LinkOmada Es224g FirmwareAll versions
Tp-LinkOmada Es220gp FirmwareAll versions
Tp-LinkOmada Es216g FirmwareAll versions
Tp-LinkOmada Es210gmp FirmwareAll versions
Tp-LinkOmada Es210gp FirmwareAll versions
Tp-LinkOmada Es208gp FirmwareAll versions
Tp-LinkOmada Es208g FirmwareAll versions
Tp-LinkOmada Es206gp FirmwareAll versions
Tp-LinkOmada Es205gp FirmwareAll versions
Tp-LinkOmada Es205g FirmwareAll versions
Tp-LinkOmada Es220gmp FirmwareAll versions
Tp-LinkOmada Es1024ge FirmwareAll versions
Tp-LinkOmada Ds1016ge FirmwareAll versions
Tp-LinkOmada Ds108ge FirmwareAll versions
Tp-LinkOmada Ds105ge FirmwareAll versions
Tp-LinkOmada Ds1008x FirmwareAll versions
Tp-LinkOmada Ds105x FirmwareAll versions

Showing 50 of 112 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2025-15627?
A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications.
How severe is CVE-2025-15627?
CVE-2025-15627 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2025-15627?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-15627?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST