- TP-Link fixed a total of 15 vulnerabilities in the ZTP solution that powers its Omada networking ecosystem after the researchers proved that it is possible to exploit the combination of all these flaws to compromise an entire network.
- These vulnerabilities are not limited to just routers but include Omada controllers, gateways, switches, access points, cloud services, and many other components.
- The researchers found over 1,800 Omada controllers exposed on the internet, making the exploitation threat very real. It would be wise at this point to perform firmware updates.
TP-Link has released patches for 15 security holes in the zero-touch provisioning mechanism of its Omada network devices. Attackers could chain the flaws with previously disclosed bugs to give hackers remote code execution (RCE) on business networks.
This fix comes after Forescout’s Vedere Labs revealed the vulnerabilities to attendees at the Black Hat USA security conference. They focused their research on the Omada Zero-Touch Provisioning (ZTP) capability.
This feature allows network devices to configure themselves automatically after being connected. It saves time for IT teams, but researchers found that weaknesses in the process could also become an entry point for attackers.
The Scale of Exposure
The newly disclosed flaws do not simply affect one product. They span Omada controllers, gateways, switches, wireless access points, optical line terminal (OLT) platforms, cloud services, and mobile applications used to manage the platform.
However, the impact of these vulnerabilities extends beyond just Omada devices. Some flaws also affect other TP-Link products and services, including IP cameras, smart home IoT devices, and mobile applications.
The researchers also noted the broad reach of TP-Link’s management software. The Omada and Omada Guard Android apps together have more than one million downloads, while TP-Link apps have collectively exceeded 70 million downloads. They estimated that around 3 to 7 million active user accounts might be under threat.
Forescout found a total of more than 1,800 Omada controllers that are accessible through the internet, despite TP-Link recommending not to expose such controllers on the Internet.
In general, controllers are supposed to remain hidden from the web behind the firewall. Internet-facing deployments increase the chances that attackers could discover vulnerable systems and attempt exploitation.
How the Attack Works
Zero-touch provisioning allows IT professionals to provision remote network devices such as routers, switches, and access points. They won’t need to go on-site to manually set each up. The controller just sends out all the settings and credentials automatically.
This convenience creates a single point of failure, says Forescout’s VP of Research, Daniel dos Santos. This is possible because systems responsible for deploying and managing devices can create entirely new attack scenarios when they have weaknesses.
The biggest concern about this discovery is not just one vulnerability. But the researchers noticed something troubling. They found that attackers can connect a bunch of security weaknesses to pull off some serious damage.
By combining these new flaws with two earlier command-injection bugs (CVE-2025-7850 and CVE-2025-7851), attackers can break Omada’s chain of trust.
For example, someone working remotely could predict device serial numbers and spot which equipment is sitting around, just waiting to be adopted by a controller. That opens the door for further attacks.
They can also use it to obtain MAC addresses. After that, the attacker will act as though he is a genuine device and take advantage of the race conditions in the cloud implementation process, and prove his identity by applying the default authentication.
This causes the controller to expose sensitive info such as usernames, the MD5 password hashes, and sometimes even the VPN key.
In another instance, attackers could inject JavaScript into the web interface of the controller, using it to phish the admin. This enables them to trick an administrator into revealing cloud management credentials.
With these credentials, they can reconfigure managed devices and create VPN tunnels into the internal network. Eventually, the attackers could exploit the earlier command injection flaws to gain even greater control over managed devices.
The researchers grouped the vulnerabilities into four main categories:
- Client-side code execution
- Information disclosure
- Device hijacking and spoofing
- Compromise of encrypted communications
Individually, some of these bugs appear limited. Combined, they can undermine the trust relationship between devices, controllers, and the cloud management platform.
The Certificate Problem
A hard-coded TLS certificate and private key are baked into Omada’s controllers. This key proves a controller is genuine. Pull it off one controller and you can convince client devices that your machine is legitimate.
Cloud connections run an additional identity check, but removing the controller’s hostname and replacing it with its IP address can bypass it.
This same chain of trust appears across other TP-Link product lines, including VIGI cameras, Festa routers, and Tapo and Kasa smart home devices. One set of certificates affects five product families. A compromised Omada account could potentially reach linked camera deployments.
TP-Link Urges Customers to Update Immediately
The patches and security advisories for all affected products are now available. All users need to do is install the latest firmware. Some cloud services update themselves automatically. But others require a manual upgrade.
TP-Link recommended that users set up strong and unique admin passwords and turn on TFA where applicable. Keeping the mobile applications updated is also as important. Suspect a compromise? Change password and other credentials ASAP. It’s also important to monitor networks for unusual activity.
For organizations using Omada, these findings further reinforce that convenient features such as zero-touch provisioning make for appealing targets for attacks. With the growing trend of device deployment through automation within organizations, securing the onboarding process is becoming just as crucial as device security.
The urgency of patching network vulnerabilities is underscored by recent Microsoft warnings about actively exploited Windows flaws being used by Russian-linked attackers, a reminder that timely updates across all systems are essential
Share this article
About the Author
Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.
More from Rebecca JamesRelated Posts
Firefox Users on iOS Can Now Block Ads without an Extension
Mozilla is slowly rolling out a built-in ad blocker for Firefox on iPhones and iPads, no extension n...
Suspected Chinese Hackers Exploit Critical VMware vCenter Flaw Across 47 Countries
Several servers across 47 countries record a compromise via an exploit of Vmware vCenter directory-t...
WhatsApp Tests On-Device Scam Alert without Reading User Messages
WhatsApp is testing a new tool called Scam Alert that spots scam messages right on your phone. The t...
Apple Faces Lawsuit Over Claims that iCloud Private Relay Leaks User IP Addresses
A law firm sued Apple, saying its Private Relay tool did not protect user privacy as promised. Exper...
Hackers Exploit TrueConf Servers to Distribute Malware Through Fake Software Updates
A hacker group named Head Mare broke into TrueConf video meeting servers and swapped safe installers...
New NatJack Attack Exposes Hidden Weakness in How Networks Handle Internet Connections
Security researcher Malcolm Stagg has uncovered NatJack, a new class of attacks that exploits a fund...