15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic
ResearchTP-Link OmadaOur summary
Researchers from Forescout's Vedere Labs discovered 15 critical vulnerabilities in TP-Link's Omada networking products, enabling remote attackers to hijack routers, steal administrative credentials, and create unauthorized VPN tunnels into internal networks. These flaws affect Omada routers, switches, access points, and even devices in four other TP-Link product lines due to shared certificate chains. Most issues have been patched, though four remain without CVE identifiers and two cannot be fixed via firmware updates. Attackers can exploit predictable serial numbers and flawed authentication mechanisms to bypass security controls and compromise devices at scale.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.