TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover
ResearchOmadaVIGIOur summary
Security researchers at Forescout have uncovered 15 critical vulnerabilities in TP-Link’s Omada networking ecosystem, particularly affecting the zero-touch provisioning (ZTP) systems used for automated device setup. These flaws, including hardcoded cryptographic keys, weak certificate validation, and predictable device identifiers, can be combined with previously reported issues (CVE-2025-7850 and CVE-2025-7851) to enable remote code execution and full network infiltration. Attackers could exploit these weaknesses to gain administrative control over cloud controllers and infiltrate internal networks. TP-Link has issued patches for part of the report, but some fixes won’t arrive until late 2026.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.