A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments.
History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link omada Access Point
Tp-link omada Gateways
Tp-link omada Olts
Tp-link omada Switches
Vendors & Products Tp-link
Tp-link omada Access Point
Tp-link omada Gateways
Tp-link omada Olts
Tp-link omada Switches

Wed, 05 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments.
Title Weak Credential Storage in TP-Link Omada Devices
Weaknesses CWE-759
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published: 2026-08-03T17:51:52.265Z

Updated: 2026-08-03T18:29:33.225Z

Reserved: 2026-04-10T16:33:57.776Z

Link: CVE-2025-15631

cve-icon Vulnrichment

Updated: 2026-08-03T18:29:26.279Z

cve-icon NVD

No data.

cve-icon Redhat

No data.