CVE Tools

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover

SecurityWeekBy Eduard Kovacs

ResearchOmadaVIGI

Our summary

Security researchers at Forescout have uncovered 15 critical vulnerabilities in TP-Link’s Omada networking ecosystem, particularly affecting the zero-touch provisioning (ZTP) systems used for automated device setup. These flaws, including hardcoded cryptographic keys, weak certificate validation, and predictable device identifiers, can be combined with previously reported issues (CVE-2025-7850 and CVE-2025-7851) to enable remote code execution and full network infiltration. Attackers could exploit these weaknesses to gain administrative control over cloud controllers and infiltrate internal networks. TP-Link has issued patches for part of the report, but some fixes won’t arrive until late 2026.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store