TP-Link Omada zero-touch provisioning flaws can let attackers take over managed network devices

Researchers say multiple flaws in TP-Link’s Omada setup system can be chained to seize control of whole fleets of routers, switches, and access points. Forescout disclosed 15 vulnerabilities in Omada zero-touch provisioning (automatic device setup), 11 with CVEs, involving hardcoded keys and certificates, weak certificate checks, insecure credential transmission, a cloud adoption race condition, and controller cross-site scripting. The attack chains can also use earlier RCE flaws CVE-2025-7850 and CVE-2025-7851, and 1,800 internet-exposed Omada controllers were observed.
Why it matters: Organizations using TP-Link Omada could lose control of the network gear that connects users and systems, especially if controllers are exposed online. Admins should apply TP-Link patches and advisories, avoid exposing controllers to the internet, and review device adoption and credential-handling practices now.

Sources

TP-Link patches Omada ZTP flaws allowing hackers to breach networks
Bill Toulas 2026.08.04 97% relevant
This article updates the same underlying TP-Link Omada zero-touch provisioning flaw set with confirmation that TP-Link has now patched 15 vulnerabilities, names the new CVE ranges, and adds vendor remediation guidance plus attack-chain details tying them to CVE-2025-7850 and CVE-2025-7851.
TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover
Eduard Kovacs 2026.08.04 100% relevant
This article establishes a new story by disclosing a distinct set of 15 TP-Link Omada ZTP vulnerabilities and practical full-network takeover chains, not a follow-up to an existing tracked event.
← Back to all stories