CVE-2025-15629

Published Aug 3, 2026

Last updated 13 days ago

Overview

Description
A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be able to recover session encryption keys and decrypt affected communications.
Source
f23511db-6c3e-4e32-a477-6aa17d310630
NVD status
Analyzed
Products
omada_oc200_v3_firmware, omada_oc300_firmware, omada_oc400_firmware, omada_fusion_2.5g_firmware, omada_er707-m2_firmware, omada_er7206_firmware, omada_er706w_firmware, omada_er8411_firmware, omada_er605_firmware, omada_er7412-m2_firmware, omada_er706w-4g_firmware, omada_er703wp-4g-outdoor_firmware, omada_er706wp-4g_firmware, omada_s7500-24y4c_firmware, omada_s7500-26xf6y_firmware, omada_s6500-48mpp6y_firmware, omada_s6500-24mpp4y_firmware, omada_s6500-48gp6xf_firmware, omada_s6500-48g6xf_firmware, omada_s6500-24gp4xf_firmware, omada_s6500-24g4xf_firmware, omada_sx6632yf_firmware, omada_sx3032f_firmware, omada_sx3016f_firmware, omada_sx3008f_firmware, omada_sg3428xf_firmware, omada_sx3832mpp_firmware, omada_sx3832_firmware, omada_sx3206hpp_firmware, omada_sg3428xpp-m2_firmware, omada_sg3428x-m2_firmware, omada_sg3218xp-m2_firmware, omada_sg3210xhp-m2_firmware, omada_sg3210x-m2_firmware, omada_sg2210xmp-m2_firmware, omada_sg6654xhp_firmware, omada_sg6654x_firmware, omada_sg6428xhp_firmware, omada_sg6428x_firmware, omada_sg5452xmpp_firmware, omada_sg5452x_firmware, omada_sg5428xmpp_firmware, omada_sg5428x_firmware, omada_sg3452xmpp_firmware, omada_sg3452xp_firmware, omada_tl-sg3452x_firmware, omada_sg3428xmpp_firmware, omada_sg3428xmp_firmware, omada_sg3428x_firmware, omada_sg2005p-pd_firmware, omada_sg3452p_firmware, omada_sg3452_firmware, omada_sg3428mp_firmware, omada_sg3428_firmware, omada_sg3210_firmware, omada_tl-sg3210_firmware, omada_sg2452lp_firmware, omada_sg2428p_firmware, omada_sg2428lp_firmware, omada_sg2218p_firmware, omada_sg2218_firmware, omada_sg2016p_firmware, omada_sg2210mp_firmware, omada_sg2210p_firmware, omada_sg2008p_firmware, omada_sg2008_firmware, omada_sg2206mp_firmware, omada_es210xpp-m2_firmware, omada_es210x-m2_firmware, omada_es206xpp-m2_firmware, omada_es206x-m2_firmware, omada_es228gmp_firmware, omada_es228gp_firmware, omada_es224g_firmware, omada_es220gp_firmware, omada_es216g_firmware, omada_es210gmp_firmware, omada_es210gp_firmware, omada_es208gp_firmware, omada_es208g_firmware, omada_es206gp_firmware, omada_es205gp_firmware, omada_es205g_firmware, omada_es220gmp_firmware, omada_es1024ge_firmware, omada_ds1016ge_firmware, omada_ds108ge_firmware, omada_ds105ge_firmware, omada_ds1008x_firmware, omada_ds105x_firmware, omada_ds108g-m2_firmware, omada_ds105g-m2_firmware, omada_ds1024g_firmware, omada_ds1016g_firmware, omada_ds110gmp_firmware, omada_ds108g_firmware, omada_ds106gpp_firmware, omada_ds106p_firmware, omada_ds105g_firmware, omada_ds111p_firmware, omada_ds1018gmp_firmware, omada_ds108gp_firmware, omada_ds105gp_firmware, omada_ies210gpp_firmware, omada_ies206gpp_firmware, omada_ies208g_firmware, omada_ies206g_firmware, omada_eap660hd_firmware, omada_eap620hd_firmware, omada_eap610_firmware, omada_eap615-wall_firmware, omada_eap610-outdoor_firmware

Risk scores

CVSS 4.0

Type
Secondary
Base score
6.9
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

f23511db-6c3e-4e32-a477-6aa17d310630
CWE-331

Social media

Hype score
Not currently trending

Configurations