Impact
During the Omada device adoption process a weak hashing algorithm is used to protect authentication credentials. This cryptographic weakness allows an attacker who intercepts the adoption traffic to recover the transmitted credentials and then gain unauthorized access to the managed device or the controller‑managed environment. The impact is the compromise of confidentiality and integrity of device management, potentially leading to full control of the network infrastructure.
Affected Systems
TP-Link Omada Access Points, Omada App, Omada Gateways, Omada Switches, Omada Controllers, and Omada OLTs are affected. No specific version information was provided, so any device running the current firmware bundle is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate risk with the potential for impact on a wide range of devices. The EPSS score is not available, so the current exploitation probability is unknown, but the vulnerability is not listed in the CISA KEV catalog. Because the weakness involves weak hashing of credentials, an attacker only needs network access to the adoption traffic; intercepting or sniffing that traffic allows credential recovery with no additional privileges. Once credentials are recovered, the attacker can authenticate as the site manager and gain full device control.
OpenCVE Enrichment