CVE detail
CVE-2025-15630
A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of provisioning information intended for a legitimate device.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 13.9 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 3
- within the 30d window
- Peak daily
- 3
- highest bucket
Evidence
Source links by recency
3 source links · newest first
- https://www.tp-link.com/us/support/faq/5216/www.tp-link.com
No excerpt available.
Vendor Advisorywww.tp-link.comAug 3, 2026, 7:16 PM - https://www.omadanetworks.com/us/support/download/www.omadanetworks.com
No excerpt available.
referencewww.omadanetworks.comAug 3, 2026, 7:16 PM - https://www.omadanetworks.com/en/support/download/www.omadanetworks.com
No excerpt available.
referencewww.omadanetworks.comAug 3, 2026, 7:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-15629CVSS 6.9 · Medium
A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predicta…
- CVE-2025-15544CVSS 6.9 · Medium
A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak has…
- CVE-2025-15631CVSS 5.7 · Medium
A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection.…
- CVE-2025-9291CVSS 7.7 · High
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate th…
- CVE-2025-15628CVSS 8.2 · High
Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtain…
- CVE-2025-15627CVSS 6.9 · Medium
A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges betwe…