TP-Link Omada Products Authentication Weakness Vulnerability Allowing Interception and Forging of Adoption Traffic

Vulnerability

An authentication weakness has been identified in TP-Link Omada Controllers, Gateways, and Access Points during the controller-device adoption process. This vulnerability arises from improper handling of random values, allowing an attacker with advanced network positioning to intercept adoption traffic and forge valid authentication through offline precomputation. As a result, sensitive information could be exposed, compromising confidentiality.

Impact

Exploitation of this vulnerability could lead to unauthorized interception of adoption traffic and forgery of authentication, potentially allowing attackers to access sensitive information and disrupt the normal functioning of the affected devices.

Remediation

Users are advised to download and update to the latest firmware version available on the TP-Link Omada Download Center. After upgrading, it is recommended to change the password to mitigate the risk of password leakage.

Added: Jan 23, 2026, 12:26 AM
Updated: Jan 23, 2026, 12:26 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
4.5
remediation
8.3
relevance
2.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.