HIGH

CVE-2025-15629

Tp-link Omada Oc200 V3 Firmware 2026-08-03 CVSS v3.1
CVSS
7.5

Description

A cryptographic
weakness exists in the Omada adoption protocol where session encryption keys
used to protect communications between controllers and managed devices may be
predictable due to insufficient entropy in session key generation.









An attacker
who successfully intercepts adoption-related communications may be able to recover
session encryption keys and decrypt affected communications.

Weakness (CWE)

CWE-331

EPSS Score

0.18%
Probability of exploitation in next 30 days
7.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE