CVE Tools

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

BleepingComputerBy Bill Toulas

PatchTP-Link Omada

Our summary

TP-Link has addressed 15 critical security flaws in the Zero-Touch Provisioning (ZTP) system of its Omada network devices, which could be exploited to gain remote code execution or hijack devices. Discovered by Forescout’s Vedere Labs, these issues include hardcoded keys, information leaks, and spoofing risks. Attackers could chain them with previously reported vulnerabilities to infiltrate networks. Affected products include Omada controllers, gateways, switches, access points, and mobile apps. Users should update their firmware immediately to mitigate potential breaches.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store