Impact
Affected Omada devices use a hard‑coded certificate that is shared across all deployments. When an attacker obtains this embedded certificate, they can use it to pose as a legitimate controller or device and intercept communications between controllers and managed devices. This is a classic example of CWE‑798 – use of hard‑coded credentials – and allows the attacker to compromise confidentiality and integrity of network traffic.
Affected Systems
The vulnerability affects TP Link Systems Inc.'s Omada family: Access Points, Gateways, OLTs, Switches, and Controllers. All firmware versions that employ the shared certificate are potentially impacted; no specific version range is provided.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability. Although the EPSS score is not available and the issue is not listed in CISA KEV, the lack of publicly known exploits does not diminish the risk to organizations that deploy these devices. Attacks would require an attacker to acquire the embedded certificate and then use it to authenticate to the controller or device, thereby enabling a man‑in‑the‑middle operation. The description does not specify a remote exploit vector, so the likely attack path would involve either local access or theft of the certificate through the device’s file system or via vendor documentation.
OpenCVE Enrichment