CVE Tools

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic

Help Net SecurityBy Mirko Zorz

ResearchTP-Link Omada

Our summary

Researchers from Forescout's Vedere Labs discovered 15 critical vulnerabilities in TP-Link's Omada networking products, enabling remote attackers to hijack routers, steal administrative credentials, and create unauthorized VPN tunnels into internal networks. These flaws affect Omada routers, switches, access points, and even devices in four other TP-Link product lines due to shared certificate chains. Most issues have been patched, though four remain without CVE identifiers and two cannot be fixed via firmware updates. Attackers can exploit predictable serial numbers and flawed authentication mechanisms to bypass security controls and compromise devices at scale.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store