Impact
A cryptographic weakness exists in the TP‑Link Omada adoption protocol where hard‑coded keys are used to establish trust between controllers and managed devices. An attacker can exploit this to impersonate a controller or a device, intercept and potentially forge adoption‑related communications, thereby gaining unauthorized access to the network and sensitive configuration data.
Affected Systems
The vulnerability affects TP‑Link Omada Access Points, Gateways, Switches, and Controllers. Specific firmware versions are not listed, so the impact applies to all firmware that still includes the hard‑coded keys.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. The EPSS score is not provided, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is through the device adoption process, which can be triggered either locally or remotely if an attacker can reach the adoption traffic. No official workaround is listed, so the risk remains unless mitigated by a firmware update or network controls.
OpenCVE Enrichment