TP-Link Omada ZTP flaws allow chained network takeovers
Forescout disclosed 15 vulnerabilities in TP‑Link Omada ZTP that can be chained to give attackers administrative control of controllers and fleets of managed devices.
Forescout researchers disclosed 15 vulnerabilities in TP‑Link’s Omada zero‑touch provisioning (ZTP) systems that can be chained to give attackers administrative control of Omada controllers and allow takeover of managed routers, switches and access points.
The flaws affect the ZTP protocols that let devices be automatically configured by cloud, hardware or software controllers. Forescout identified hardcoded cryptographic keys and certificates, insecure transmission of device and site credentials, weak certificate validation that allows man‑in‑the‑middle interception, a race condition in cloud‑based device adoption, a cross‑site scripting flaw in controller web interfaces, predictable device serial numbers and default credentials.
Eleven of the 15 issues have been assigned CVE identifiers. TP‑Link declined to assign CVEs to the remaining four, describing them as low severity. Forescout combined several of the newly disclosed flaws with two previously reported remote code execution vulnerabilities, CVE‑2025‑7850 and CVE‑2025‑7851, to demonstrate practical attack chains.
In one scenario an external attacker with no prior network access can exploit the cloud adoption race condition to intercept credentials and configuration data, seize administrative control of a user’s cloud controller account and establish a foothold inside the internal network. Other scenarios require an attacker on the same local network to impersonate a controller or a device to capture credentials, decrypt traffic or gain unauthorized management access. Some attacks depend on an administrator approving a spoofed device; others can be completed without local interaction. Because a single Omada controller can manage an entire fleet, a compromised controller could be used to push malicious configurations or commands to many devices and researchers warned chains might lead to root‑level command execution on affected hardware.
Forescout reported approximately 1,800 Omada controllers reachable from the public internet. The research team also found related weaknesses in other TP‑Link product lines, including the VIGI IP camera platform, Festa routers and the Tapo and Kasa smart home products. TP‑Link has released patches and advisories addressing some of the reported problems and indicated fixes for structural weaknesses may not be finished until later in 2026; the vendor also said certain low‑severity issues will not be patched.
Forescout will present a summary of the technical findings at the Black Hat security conference in Las Vegas. Network administrators running Omada are advised to ensure controllers are not exposed to the internet, apply available patches, change default credentials and monitor for unusual device adoption activity.








