TP-Link Patches 15 Zero-Touch Provisioning Flaws in Omada Network Devices
TP-Link has addressed 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada business networking devices, which could be chained with previously disclosed flaws to enable remote code execution (RCE). The vulnerabilities were discovered by Forescout’s Vedere Labs researchers and disclosed at the Black Hat USA security conference.
Omada, TP-Link’s enterprise-grade product line, includes Wi-Fi access points, switches, gateways, and VPN routers, commonly used by small to medium-sized businesses and larger enterprises. ZTP allows IT teams to deploy and configure devices remotely without manual on-site setup.
The 15 flaws affect multiple TP-Link products, including Omada controllers, gateways, switches, access points, OLT platforms, cloud services, and mobile applications. They span hard-coded cryptographic keys, information disclosure, device hijacking, client-side code execution, and the interception of encrypted communications. When combined with two previously disclosed command-injection vulnerabilities (CVE-2025-7850 and CVE-2025-7851), these flaws could allow attackers to compromise the chain of trust and infiltrate networks.
Eleven of the vulnerabilities received CVE identifiers:
- CVE-2025-9289 through CVE-2025-9293
- CVE-2025-15544
- CVE-2025-15627 through CVE-2025-15631
The remaining four flaws involve insecure device adoption processes, including reliance on predictable serial numbers, default credentials, and unauthenticated temporary download links.
Forescout outlined an attack scenario where a remote attacker could exploit predictable serial numbers to impersonate a device during cloud adoption, authenticate using default credentials, and extract sensitive data such as cleartext usernames, unsalted MD5 password hashes, and VPN keys. Attackers could also inject malicious JavaScript into the controller’s interface to phish administrators and steal cloud credentials, enabling further network compromise.
Over 1,800 internet-exposed Omada controllers were identified, despite such deployments typically not being intended for direct public access. TP-Link’s mobile applications, including Omada and Omada Guard, have over 1.1 million downloads on Google Play, with TP-Link apps collectively serving 3 to 7 million active accounts.
TP-Link has released firmware updates to mitigate the vulnerabilities, available through its Omada download portal.
TP-Link TPRM report: https://www.rankiteo.com/company/omadabytp-link
"id": "oma1785889428",
"linkid": "omadabytp-link",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Small to medium-sized '
'businesses, larger enterprises, '
'and users of Omada products',
'industry': 'Networking and Telecommunications',
'name': 'TP-Link',
'size': 'Large (3-7 million active accounts)',
'type': 'Company'}],
'attack_vector': 'Remote',
'data_breach': {'data_encryption': 'Interception of encrypted communications '
'possible',
'personally_identifiable_information': 'Yes (usernames, '
'password hashes)',
'sensitivity_of_data': 'High (cleartext usernames, unsalted '
'MD5 password hashes, VPN keys)',
'type_of_data_compromised': 'Credentials, VPN keys, '
'personally identifiable '
'information (PII)'},
'description': 'TP-Link has addressed 15 vulnerabilities in the zero-touch '
'provisioning (ZTP) mechanism of its Omada business networking '
'devices, which could be chained with previously disclosed '
'flaws to enable remote code execution (RCE). The '
'vulnerabilities were discovered by Forescout’s Vedere Labs '
'researchers and disclosed at the Black Hat USA security '
'conference. The flaws affect multiple TP-Link products, '
'including Omada controllers, gateways, switches, access '
'points, OLT platforms, cloud services, and mobile '
'applications. They span hard-coded cryptographic keys, '
'information disclosure, device hijacking, client-side code '
'execution, and interception of encrypted communications. When '
'combined with two previously disclosed command-injection '
'vulnerabilities (CVE-2025-7850 and CVE-2025-7851), these '
'flaws could allow attackers to compromise the chain of trust '
'and infiltrate networks.',
'impact': {'data_compromised': 'Cleartext usernames, unsalted MD5 password '
'hashes, VPN keys, cloud credentials',
'identity_theft_risk': 'High (due to exposure of PII and '
'credentials)',
'operational_impact': 'Network infiltration, device hijacking, '
'remote code execution',
'systems_affected': 'Omada controllers, gateways, switches, access '
'points, OLT platforms, cloud services, mobile '
'applications'},
'initial_access_broker': {'entry_point': 'Predictable serial numbers, default '
'credentials, unauthenticated '
'temporary download links'},
'investigation_status': 'Resolved (patches released)',
'post_incident_analysis': {'corrective_actions': 'Firmware updates to address '
'vulnerabilities, improved '
'authentication and '
'encryption practices',
'root_causes': 'Hard-coded cryptographic keys, '
'information disclosure, insecure '
'device adoption processes, lack of '
'proper authentication mechanisms'},
'recommendations': 'Apply firmware updates immediately, avoid exposing Omada '
'controllers to the internet, review device adoption '
'processes for security weaknesses, and monitor for '
'unauthorized access.',
'references': [{'source': 'Forescout’s Vedere Labs'},
{'source': 'Black Hat USA security conference'},
{'source': 'TP-Link Omada download portal'}],
'response': {'remediation_measures': 'Firmware updates released via TP-Link’s '
'Omada download portal',
'third_party_assistance': 'Forescout’s Vedere Labs researchers'},
'title': 'TP-Link Patches 15 Zero-Touch Provisioning Flaws in Omada Network '
'Devices',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': ['CVE-2025-9289',
'CVE-2025-9290',
'CVE-2025-9291',
'CVE-2025-9292',
'CVE-2025-9293',
'CVE-2025-15544',
'CVE-2025-15627',
'CVE-2025-15628',
'CVE-2025-15629',
'CVE-2025-15630',
'CVE-2025-15631',
'CVE-2025-7850',
'CVE-2025-7851',
'Insecure device adoption processes (predictable '
'serial numbers, default credentials, '
'unauthenticated temporary download links)']}