


Perceptive Security
SOC/SIEM Consultancy

TP-Link patches Omada ZTP flaws allowing hackers to breach networks
Published:
5 August 2026 at 00:18:20
Alert date:
5 August 2026 at 01:03:20
Source:
bleepingcomputer.com
Network Infrastructure, Mobile & IoT, Zero-Day Vulnerabilities, Cloud & Virtualization
TP-Link has released patches addressing 15 vulnerabilities discovered in the zero-touch provisioning (ZTP) mechanism of its Omada network devices. These flaws can be chained together with previously disclosed vulnerabilities to achieve remote code execution (RCE). The affected product line is widely used in enterprise and SMB network environments. The combination of new and old vulnerabilities creates a significant attack surface for threat actors targeting network infrastructure. TP-Link urges users to apply the patches promptly to mitigate the risk of network compromise.
Technical details
Forescout's Vedere Labs discovered 15 vulnerabilities in TP-Link Omada's Zero-Touch Provisioning (ZTP) mechanism, disclosed at Black Hat USA. The flaws span four impact categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications. Specific issues include hard-coded cryptographic keys, information disclosure, remote code execution, device hijacking and spoofing, client-side JavaScript injection, and interception or compromise of encrypted communications. When combined with two previously disclosed command-injection CVEs (CVE-2025-7850 and CVE-2025-7851), attackers can chain these flaws to compromise Omada's chain of trust. In one attack scenario: (1) An attacker enumerates predictable device serial numbers to obtain MAC addresses and identify unadopted devices. (2) The attacker impersonates a device, exploits a race condition during cloud adoption, and authenticates using default credentials. (3) The controller then discloses device configuration including cleartext usernames, unsalted MD5 password hashes, and potentially VPN keys. (4) The attacker injects JavaScript into the controller's admin interface to phish administrators and steal cloud-controller credentials. (5) With stolen credentials, the attacker reconfigures managed devices, creates VPN tunnels into the internal network, and exploits command-injection flaws to fully compromise network equipment. 11 of the 15 flaws received CVE identifiers; 4 did not (covering: device adoption based solely on serial number, default credentials during initial adoption, predictable serial numbers, and unauthenticated temporary download links). Over 1,800 internet-accessible Omada controllers were identified by Forescout despite not being intended for direct internet exposure.
Mitigation steps:
1. Update firmware: Visit TP-Link's Omada download portal (https://support.omadanetworks.com/en/download/) and apply the latest firmware images for your device model. 2. Use strong, unique administrator credentials and avoid default credentials. 3. Enable multi-factor authentication (MFA) on Omada controller and cloud accounts. 4. Rotate all secrets (passwords, VPN keys, credentials) if compromise is suspected. 5. Update Omada and Omada Guard mobile applications to the latest versions. 6. Monitor network traffic for suspicious activity. 7. Do not expose Omada Controllers directly to the internet; place them behind a firewall or on a segmented network. 8. Audit device adoption procedures and restrict adoption to known, verified serial numbers where possible.
Affected products:
TP-Link Omada Controllers
TP-Link Omada Gateways
TP-Link Omada Switches
TP-Link Omada Access Points
TP-Link Omada OLT Platforms
TP-Link Omada Cloud Services
TP-Link Omada Mobile Application (Android)
TP-Link Omada Guard Mobile Application (Android)
TP-Link IP Cameras
TP-Link Smart Home IoT Devices
TP-Link VPN Routers
TP-Link PoE Switches
Related links:
https://www.forescout.com/blog/new-tp-link-router-vulnerabilities-exploiting-zero-touch-provisioning/
https://support.omadanetworks.com/us/document/130627/
https://support.omadanetworks.com/en/download/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
