CVE-2025-15628

Published: Ago 03, 2026 Last Modified: Ago 03, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,2
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Attack Vector: adjacent
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

Affected
Omada devices rely on embedded certificates that are shared across deployments
to establish trust between controllers and managed devices.

An attacker
who obtains the embedded certificates may be able to impersonate trusted
controllers or devices and intercept affected communications.

798

Use of Hard-coded Credentials

Draft
Common Consequences
Security Scopes Affected:
Access Control Integrity Confidentiality Availability Other
Potential Impacts:
Bypass Protection Mechanism Read Application Data Gain Privileges Or Assume Identity Execute Unauthorized Code Or Commands Other
Applicable Platforms
Technologies: Mobile, ICS/OT
View CWE Details
https://www.omadanetworks.com/en/support/download/
https://www.omadanetworks.com/us/support/download/
https://www.tp-link.com/us/support/faq/5216/