CVE-2025-15628

TP-Link · Omada Gateways

TP-Link Omada devices use shared embedded certificates to establish trust between controllers and managed devices, creating a risk of unauthorized impersonation.

Executive summary

A vulnerability in TP-Link Omada devices involving hard-coded, shared certificates allows potential attackers to impersonate trusted network components and intercept communications.

Vulnerability

This vulnerability (CWE-798) involves the use of hard-coded, shared embedded certificates across different deployments. The attack vector is adjacent (AV:A), meaning an attacker must be on the same local network segment to exploit the flaw, but no authentication is required.

Business impact

The CVSS score of 8.2 (High) reflects the significant risk posed by the ability to intercept sensitive management traffic. Successful exploitation could lead to the compromise of network integrity, as an attacker could masquerade as a legitimate controller to push unauthorized configurations or capture sensitive data moving across the management plane.

Remediation

Immediate Action: Update all affected Omada devices to the latest firmware versions available via the official TP-Link Omada download center.

Proactive Monitoring: Monitor network access logs for anomalous controller-to-device communication patterns or unexpected certificate handshake failures.

Compensating Controls: Segment management traffic on a dedicated, isolated VLAN to restrict unauthorized access to the management plane.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Given the high severity of this vulnerability, administrators should prioritize updating all Omada infrastructure components immediately. Addressing this flaw is essential to maintaining the trust relationship between controllers and managed hardware and preventing potential network-wide compromise.