TP-Link fixes Omada ZTP flaws that could enable network compromise
TP-Link has released fixes for 15 vulnerabilities affecting the zero-touch provisioning (ZTP) system used by its Omada networking products. Researchers at Forescout’s Vedere Labs say the issues could...
TP-Link has released fixes for 15 vulnerabilities affecting the zero-touch provisioning (ZTP) system used by its Omada networking products. Researchers at Forescout’s Vedere Labs say the issues could be combined with previously disclosed command-injection bugs to gain control of network infrastructure.
Omada is TP-Link’s business-focused portfolio, covering wireless access points, switches, gateways, VPN routers and related cloud and mobile services. Its ZTP capability allows organizations and managed service providers to deploy equipment remotely using predefined configurations rather than configuring each device on site.
The newly reported weaknesses span several impact areas, including hard-coded encryption keys, information exposure, device hijacking and spoofing, remote and client-side code execution, and the interception or compromise of protected communications. Eleven of the issues have CVE identifiers ranging from CVE-2025-9289 through CVE-2025-9293, CVE-2025-15544, and CVE-2025-15627 through CVE-2025-15631. Four additional findings were not assigned CVE numbers.
Potential attack chain
According to Forescout, an attacker could enumerate predictable device serial numbers, identify equipment waiting to be adopted, and impersonate a device during a race condition in the cloud-adoption process. Default credentials could then allow access to configuration data, including a username, an unsalted MD5 password hash and, in some cases, VPN keys.
Researchers also described a path for injecting JavaScript into a controller’s management interface. This could be used to trick an administrator into surrendering cloud-controller credentials. With those credentials, an attacker could alter managed devices, establish VPN access to internal networks and use the earlier command-injection vulnerabilities to compromise equipment.
The affected products and services include Omada controllers, gateways, switches, access points, optical line terminal platforms, cloud infrastructure and TP-Link mobile applications. Forescout said it found more than 1,800 Omada controllers reachable from the internet, although these systems are generally not intended to be directly exposed.
Recommended actions
Organizations should obtain updated firmware from TP-Link’s Omada download portal and update associated mobile applications. Administrators should also use unique passwords, enable multifactor authentication, rotate credentials and other secrets if compromise is suspected, and monitor network activity for unusual connections or configuration changes.
