Omada gateways
TP-Link Systems Inc.- Software type
- —
- Catalog vulnerabilities
- 11
Severity across 11 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 11 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 11 vulnerability records affecting Omada gateways.
Among the 11 records analyzed by CyStack, 6 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2025-15631Weak Credential Storage in TP-Link Omada Devices | Exploitation statusNot known exploited | FixYes | Published08/03/2026 | SeverityMedium |
CVE-2025-15630Device Provisioning Race Condition in TP-Link Omada Adoption Workflow | Exploitation statusNot known exploited | FixYes | Published08/03/2026 | SeverityMedium |
CVE-2025-15629Weak Session Key Generation in TP-Link Omada Adoption Protocol | Exploitation statusNot known exploited | FixYes | Published08/03/2026 | SeverityMedium |
CVE-2025-15628Hardcoded Certificates in TP-Link Omada Device Communications | Exploitation statusNot known exploited | FixYes | Published08/03/2026 | SeverityHigh |
CVE-2025-15627Hardcoded Cryptographic Keys in TP-Link Omada Adoption Protocol Authentication | Exploitation statusNot known exploited | FixYes | Published08/03/2026 | SeverityMedium |
CVE-2025-15544Weak Credential Protection During TP-Link Omada Device Adoption | Exploitation statusNot known exploited | FixYes | Published08/03/2026 | SeverityMedium |
CVE-2025-9291Improper Certificate Validation in TP-Link Omada Cloud Communications | Exploitation statusNot known exploited | FixYes | Published08/03/2026 | SeverityHigh |
CVE-2025-7851Unauthorized root access via debug functionality | Exploitation statusNot known exploited | FixYes | Published10/21/2025 | SeverityHigh |
CVE-2025-7850Authenticated OS command execution | Exploitation statusNot known exploited | FixYes | Published10/21/2025 | SeverityCritical |
CVE-2025-6542OS command injection in multiple parameters | Exploitation statusNot known exploited | FixYes | Published10/21/2025 | SeverityCritical |
CVE-2025-6541OS command injection using information obtained from the web management interface | Exploitation statusNot known exploited | FixYes | Published10/21/2025 | SeverityHigh |