Impact
A weakness in certificate validation between TP‑Link Omada devices and their cloud controllers allows a certificate presented by an attacker to be accepted as legitimate. The verification process fails to confirm that the certificate matches the expected controller hostname, so an attacker could inject a forged certificate. If successful, the attacker can read, modify, or inject traffic between the device and controller, potentially compromising device configuration and network management data.
Affected Systems
The affected vendors are TP‑Link Systems Inc. and the impacted products are Omada Access Points, Omada Gateways, and Omada Switches. These devices use firmware that handles traffic to the cloud controller. The vulnerability exists in the communication layer that validates server certificates.
Risk and Exploitability
The CVSS score of 7.7 denotes high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but these metrics do not diminish the risk. The likely attack vector is remote, through the device’s communication with the cloud controller over the network. An attacker who can position themselves as a fake controller or intercept the certificate chain can exploit the weakness without local access. While no public exploits are reported, the flaw can be leveraged in scenarios where the controller is reachable from an untrusted network.
OpenCVE Enrichment