CVE Tools

Уязвимости в ZTP TP-Link Omada приводят к полной компрометации сети

Хакер (xakep.ru)By Мария Нефёдова

ResearchOmadaVIGI IP Cameras

Our summary

Security researchers at Forescout have disclosed 15 vulnerabilities within the zero-touch provisioning (ZTP) mechanism of TP-Link Omada corporate networking products. These flaws include hardcoded cryptographic keys and insecure certificate validation, which enable man-in-the-middle attacks and unauthorized device enrollment.

When chained with previously reported remote code execution bugs CVE-2025-7850 and CVE-2025-7851, attackers can achieve root-level access to managed switches, gateways, and access points without initial network entry. The research highlights risks spanning Omada controllers and devices, as well as related VIGI IP Cameras, Festa routers, and Tapo/Kasa smart home devices.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store