Tp-link Omada Es220gmp Firmware — known CVE vulnerabilities
Every CVE whose affected-product data names Tp-link Omada Es220gmp Firmware, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (7)
CVE-2025-15629 — CVSS 7.5 (high): A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between…
CVE-2025-15627 — CVSS 7.5 (high): A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and…
CVE-2025-15628 — CVSS 7.5 (high): Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed…
CVE-2025-9291 — CVSS 6.5 (medium): A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity…
CVE-2025-15544 — CVSS 5.9 (medium): A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site…
CVE-2025-15630 — CVSS 5.9 (medium): A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption…
CVE-2025-15631 — CVSS 5.9 (medium): A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does…