TP-Link patches Omada ZTP flaws allowing hackers to breach networks

Cybersecurity Firm Forescout Uncovers Critical Flaws in TP-Link’s Omada Network Devices

TP-Link, a leading manufacturer of networking equipment, has patched 15 vulnerabilities in its Omada zero-touch provisioning (ZTP) mechanism that could be exploited to breach networks. The flaws were discovered by Forescout’s Vedere Labs researchers and publicly disclosed at the Black Hat USA security conference.

The affected devices are part of TP-Link’s business networking product line, known as Omada, which includes Wi-Fi access points, Ethernet switches, internet gateways, and VPN routers. These products are commonly used by small to medium-sized businesses, but also marketed for enterprise-grade deployments. ZTP is a feature that allows IT teams or managed service providers (MSPs) to remotely deploy network devices without manual configuration.

Forescout’s research revealed a range of issues, including hard-coded cryptographic keys, information disclosure, remote code execution, device hijacking and spoofing, client-side code execution, and interception or compromise of encrypted communications. Attackers could combine these flaws with two previously disclosed command-injection vulnerabilities to compromise Omada’s chain of trust and infiltrate networks.

The researchers explained that the vulnerabilities fall into four impact categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications. When combined with the previous CVEs (CVE-2025-7850 and CVE-2025-7851), these flaws enable concrete attacks that allow attackers to infiltrate networks through controllers and client devices.

TP-Link has issued an advisory listing 15 newly disclosed flaws, with 11 receiving a tracking number from the Common Vulnerabilities and Exposures (CVE) database. The remaining four findings concern device adoption based on serial numbers, default credentials, predictable serial numbers, and files made available via unauthenticated download links.

In one attack scenario described by Forescout, a remote attacker could enumerate predictable device serial numbers to obtain MAC addresses and identify devices awaiting adoption. The attacker could then impersonate one of those devices, exploit a race condition during cloud adoption, and authenticate using default credentials. This would allow the attacker to disclose the device configuration, including sensitive information like usernames, passwords, and VPN keys.

The flaws affect Omada Controllers, Gateways, Switches, Access Points, OLT platforms, Cloud services, and TP-Link mobile applications. Forescout reports identifying over 1,800 internet-accessible Omada controllers, despite such deployments not being intended for direct internet exposure. Users are advised to visit TP-Link’s Omada download portal to source the latest firmware images for their device model.

To mitigate these vulnerabilities, it is essential to use strong, unique administrator credentials, enable multi-factor authentication (MFA), rotate all secrets when compromise is suspected, update mobile apps, and monitor network traffic for suspicious activity. This incident serves as a reminder of the importance of regular security updates and vulnerability patching in preventing attacks on networked devices.

In conclusion, the discovery of these critical flaws highlights the need for organizations to prioritize cybersecurity and stay vigilant against potential threats. By following best practices and staying informed about emerging vulnerabilities, businesses can minimize their exposure to cyber risks and protect their networks from unauthorized access.


Source: Bleeping Computer — 2026-08-04