Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Restrict sale of pet flea treatments, government urged

    August 5, 2026

    Elon Musk repeatedly one-upped his execs on SpaceX’s first earnings call

    August 5, 2026

    Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

    August 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Restrict sale of pet flea treatments, government urged
    • Elon Musk repeatedly one-upped his execs on SpaceX’s first earnings call
    • Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
    • Self Custody Is Dead. Long Live Self Custody
    • NASA’s PUNCH Sharpens Solar Storm Forecasting in First Test
    • Edward Fishman on the Top Global Chokepoints—and How to Navigate Them
    • Firefighters in Greece gain ground against wildfires near Athens
    • Charity Commission to investigate donations to illegal Israeli settlements | Charities
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    TP-Link patches Omada ZTP flaws allowing hackers to breach networks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 4, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE).

    The flaws were uncovered by Forescout’s Vedere Labs researchers, who published the full details at the Black Hat USA security conference earlier today.

    Omada is TP-Link’s business networking product line that includes Wi-Fi access points, Ethernet and PoE switches, internet gateways, and VPN routers.

    image

    They are typically used by small to medium-sized businesses, although TP-Link also markets pro-grade deployments for enterprises.

    ZTP is a way to deploy network devices without manually configuring each one on-site, allowing an IT team or managed service provider (MSP) to prepare everything remotely based on a predetermined configuration.

    Omada deployment diagram
    Omada deployment diagram
    Source: Forescout

    Some of the 15 flaws Forescout discovered also impact various TP-Link products and services, such as IP cameras, smart home IoT devices, mobile applications, and cloud accounts.

    The issues include hard-coded cryptographic keys, information disclosure, remote code execution, device hijacking and spoofing, client-side code execution, and interception or compromise of encrypted communications.

    Forescout says attackers could combine the new flaws with two previously disclosed command-injection vulnerabilities to compromise Omada’s chain of trust and infiltrate networks.

    “The vulnerabilities fall into four impact categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications,” Forescout explains.

    “Combined with two previously disclosed CVEs (CVE-2025-7850 and CVE-2025-7851), these flaws enable concrete attacks that let attackers infiltrate networks through controllers and client devices.”

    TP-Link’s advisory lists 15 newly disclosed flaws, of which 11 received the following identifiers:

    • CVE-2025-9289 through CVE-2025-9293
    • CVE-2025-15544
    • CVE-2025-15627 through CVE-2025-15631

    The remaining four findings did not receive a tracking number. They concern device adoption based only on knowing the serial number, default credentials used during initial adoption, predictable serial numbers, and files made available via unauthenticated temporary download links.

    In one attack scenario Forescout described, a remote attacker could enumerate predictable device serial numbers to obtain MAC addresses and identify devices awaiting adoption.

    The attacker could then impersonate one of those devices, exploit a race condition during cloud adoption, and authenticate using default credentials.

    This would cause the controller to disclose the device configuration, including a cleartext username, an unsalted MD5 password hash, and potentially VPN keys.

    The attacker could also inject JavaScript into the controller’s administrative interface to phish an administrator and steal their cloud-controller credentials.

    Having stolen the credentials, the attacker can then reconfigure managed devices, create VPN tunnels into the internal network, and exploit previously disclosed command-injection flaws to compromise network equipment.

    Overview of the race condition attack
    Overview of the race condition attack
    Source: Forescout

    The flaws affect Omada Controllers, Gateways, Switches, Access Points, OLT platforms, Cloud services, and TP-Link mobile applications.

    Forescout reports identifying over 1,800 internet-accessible Omada controllers, despite such deployments generally not being intended for direct internet exposure.

    As for the Android applications, Omada and Omada Guard have 1.1 downloads on Google Play, while TP-Link apps collectively have 3 to 7 million active accounts.

    Users are advised to visit TP-Link’s Omada download portal to source the latest firmware images for their device model.

    Additionally, it is recommended to use strong, unique administrator credentials, enable multi-factor authentication (MFA), rotate all secrets when compromise is suspected, update mobile apps, and monitor network traffic for suspicious activity.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    allowing breach flaws hackers networks Omada Patches TPLink ZTP
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

    Phishing service spoofs RingCentral to steal Microsoft 365 accounts

    Oligo Raises $60 Million for Runtime Security

    Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

    Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer

    Massive ChainDrop npm supply-chain attack infects hundreds of packages

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Restrict sale of pet flea treatments, government urged

    August 5, 2026

    Elon Musk repeatedly one-upped his execs on SpaceX’s first earnings call

    August 5, 2026

    Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

    August 5, 2026

    Self Custody Is Dead. Long Live Self Custody

    August 4, 2026
    Latest Posts

    Oil prices hit $100 for the first time since May

    July 23, 2026

    Pew Survey: China May Be Liked More, but It Is Celebrating a Race It Never Ran

    July 23, 2026

    Yinson Production and PTSC’s FSO heads off to Southeast Asian oil project

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Restrict sale of pet flea treatments, government urged

    August 5, 2026

    Elon Musk repeatedly one-upped his execs on SpaceX’s first earnings call

    August 5, 2026

    Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

    August 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.