Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Network Security

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover

Forescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem.

TP-Link vulnerabilities

Security researchers at Forescout have disclosed 15 new vulnerabilities in the zero-touch provisioning (ZTP) systems used by TP-Link’s Omada networking ecosystem, warning that some of the flaws can be chained to compromise entire fleets of managed devices. 

The vulnerabilities affect the ZTP protocols that allow routers, switches, and access points to be automatically configured by cloud-based, hardware, or software controllers, a process designed to reduce manual setup for network administrators managing multiple devices.

Forescout’s findings include the use of hardcoded cryptographic keys and certificates, insecure transmission of device and site credentials, weak certificate validation that enables man-in-the-middle attacks, a race condition in cloud-based device adoption, and a cross-site scripting flaw in controller web interfaces. 

Researchers also identified issues such as predictable device serial numbers and default credentials that make it easier for attackers to enumerate and hijack devices. 

Eleven of the 15 issues have been assigned CVE identifiers. TP-Link declined to assign CVEs to the remaining four, citing low severity.

By combining some of the newly discovered flaws with two previously disclosed vulnerabilities enabling remote code execution (CVE-2025-7850 and CVE-2025-7851), Forescout researchers demonstrated several practical attack paths. 

Advertisement. Scroll to continue reading.

In one scenario, an external attacker with no network access can exploit a race condition during cloud-based device adoption to intercept credentials and configuration data, ultimately gaining administrative control of a user’s cloud controller account and a foothold inside the internal network. 

Other scenarios show that attackers positioned on a local network can impersonate controllers or devices to intercept credentials, decrypt protected traffic, or gain unauthorized access. However, in some cases an administrator must approve a spoofed device for the attack to work.

Because a single compromised controller can manage an entire fleet of devices, researchers noted that a successful attack chain could allow an intruder to gain a foothold inside the network and potentially achieve root-level command execution on the Omada devices it manages.

Omada controllers should not be exposed to the internet, but Forescout said it found 1,800 instances accessible from the web.

Beyond the Omada product line, researchers found that some of the same underlying weaknesses extend to other TP-Link products, including its VIGI IP camera platform, Festa routers, and the Tapo and Kasa smart home lines. 

TP-Link has issued patches and advisories for a portion of the reported issues. The vendor indicated that remediation for some of the more structural weaknesses may not be complete until later in 2026, and some issues classified as ‘low severity’ will not be patched.

Forescout researchers will summarize the findings on Wednesday at the Black Hat cybersecurity conference in Las Vegas. 

Related: Hackers Fail to Exploit Flaw in Discontinued TP-Link Routers

Related: TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking

Related: TP-Link Patches High-Severity Router Vulnerabilities

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Veritas Capital has appointed Joel Fulton as Chief Information Security Officer.

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.