---
cve: "CVE-2025-15631"
severity: "MEDIUM"
cvss: 5.7
epss: "0.2%"
vendor: "TP Link Systems Inc."
kev: false
exploited: false
published: "2026-08-03 19:16:41"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-21T00:01:51+02:00"
---

# CVE-2025-15631

> 5.7 MEDIUM

## Beschreibung

A
cryptographic weakness exists in affected Omada devices where site credentials
are protected using a legacy hashing algorithm that does not provide sufficient
protection.









An attacker
who obtains access to stored credential data may be able to recover valid credentials
to gain unauthorized access to affected devices or management environments.

## CVSS-Vektor

```
CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Hoch | good |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://www.omadanetworks.com/us/support/download/>
- <https://www.omadanetworks.com/en/support/download/>
- <https://www.tp-link.com/us/support/faq/5216/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-15631) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
