Impact
A race condition exists in the cloud‑based Omada device adoption process. If an attacker initiates an adoption request before a legitimate device completes registration, the system may deliver provisioning data intended for the legitimate device to the attacker, resulting in disclosure of sensitive provisioning. This flaw is classified as a concurrency issue (CWE‑362).
Affected Systems
Affected vendors and products include TP Link Systems Inc. and its Omada device families – Access Points, Gateways, Switches, and Controllers. All firmware versions that employ the unpatched adoption workflow are potentially vulnerable; the advisory does not specify individual version numbers.
Risk and Exploitability
The CVSS score of 5.8 indicates moderate severity. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via the cloud adoption interface, which requires network connectivity to TP Link’s services and the ability to submit an adoption request concurrently with a legitimate device. No evidence of public exploits or tooling is cited, so the exploitation likelihood remains uncertain.
OpenCVE Enrichment