[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBUisJHrCJJ_Qof58KpV6-Sck5zugG6UrdEppjBflpqc":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"9b87a269-1a25-4ca8-adf0-1bab66a980be","TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover","tp-link-omada-ztp-vulnerabilities-chain-into-full-network-takeover-d86258","Forescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem. The post TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover appeared first on SecurityWeek.","Forescout researchers have discovered 15 vulnerabilities in TP-Link's Omada networking ecosystem, specifically within its zero-touch provisioning (ZTP) systems. These flaws, including hardcoded keys, insecure credential transmission, and weak certificate validation, can be chained together to achieve full network takeover and root-level command execution on managed devices. While TP-Link has released patches for some issues, full remediation for structural weaknesses may not be completed until late 2026.","TP-Link Omada ZTP vulnerabilities allow for full network takeover.","Security researchers at Forescout have disclosed 15 new vulnerabilities in the zero-touch provisioning (ZTP) systems used by TP-Link’s Omada networking ecosystem, warning that some of the flaws can be chained to compromise entire fleets of managed devices. The vulnerabilities affect the ZTP protocols that allow routers, switches, and access points to be automatically configured by cloud-based, hardware, or software controllers, a process designed to reduce manual setup for network administrators managing multiple devices. Forescout’s findings include the use of hardcoded cryptographic keys and certificates, insecure transmission of device and site credentials, weak certificate validation that enables man-in-the-middle attacks, a race condition in cloud-based device adoption, and a cross-site scripting flaw in controller web interfaces. Researchers also identified issues such as predictable device serial numbers and default credentials that make it easier for attackers to enumerate and hijack devices. Eleven of the 15 issues have been assigned CVE identifiers. TP-Link declined to assign CVEs to the remaining four, citing low severity. By combining some of the newly discovered flaws with two previously disclosed vulnerabilities enabling remote code execution (CVE-2025-7850 and CVE-2025-7851), Forescout researchers demonstrated several practical attack paths. Advertisement. Scroll to continue reading. In one scenario, an external attacker with no network access can exploit a race condition during cloud-based device adoption to intercept credentials and configuration data, ultimately gaining administrative control of a user’s cloud controller account and a foothold inside the internal network. Other scenarios show that attackers positioned on a local network can impersonate controllers or devices to intercept credentials, decrypt protected traffic, or gain unauthorized access. However, in some cases an administrator must approve a spoofed device for the attack to work. Because a single compromised controller can manage an entire fleet of devices, researchers noted that a successful attack chain could allow an intruder to gain a foothold inside the network and potentially achieve root-level command execution on the Omada devices it manages. Omada controllers should not be exposed to the internet, but Forescout said it found 1,800 instances accessible from the web. Beyond the Omada product line, researchers found that some of the same underlying weaknesses extend to other TP-Link products, including its VIGI IP camera platform, Festa routers, and the Tapo and Kasa smart home lines. TP-Link has issued patches and advisories for a portion of the reported issues. The vendor indicated that remediation for some of the more structural weaknesses may not be complete until later in 2026, and some issues classified as ‘low severity’ will not be patched. Forescout researchers will summarize the findings on Wednesday at the Black Hat cybersecurity conference in Las Vegas. Related: Hackers Fail to Exploit Flaw in Discontinued TP-Link Routers Related: TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking Related: TP-Link Patches High-Severity Router Vulnerabilities Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs N‑able Patches Vulnerability Exploited to Hack N-central ServersUS Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other StatesPrompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 OrganizationsSemiconductor Firm Analog Devices Discloses Data Breach1 in 5 Data Center Assets Are Within Easy Reach of AttackersCisco Secure FMC Zero-Day Exploited in the WildThreatLocker Raises $190 Million in Series F FundingCritical VM Escape Vulnerability Patched in VMware ESXi Latest News Weaponized Email AI Assistants Could Help Attackers Hijack AccountsZenity Raises $125 Million in Series C FundingObsidian Security Raises $85 Million at $1.1 Billion ValuationGemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request TamperingDecades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks150,000 Impacted by Madera Community Hospital Data BreachMicrosoft Bug Bounty Program: $20 Million Paid to 500 ResearchersNew York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MovePNC Financial Services Group has appointed Christian Winward as CISO.Brian Gumbel has joined Armadin as Chief Revenue Officer.EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.More People On The MoveExpert Insights Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Ftp-link-omada-ztp-vulnerabilities-chain-into-full-network-takeover\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F10\u002FTp-Link.jpeg","2026-08-04T12:00:00+00:00","2026-08-04T14:00:10.648569+00:00",9,[18,21,24,26,28,30],{"name":19,"type":20},"Omada","product",{"name":22,"type":23},"TP-Link","vendor",{"name":25,"type":20},"VIGI",{"name":27,"type":20},"Festa",{"name":29,"type":20},"Tapo",{"name":31,"type":20},"Kasa","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,43,45,50],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":44},{"id":32,"icon":34,"name":35,"slug":36},{"category":46},{"id":47,"icon":34,"name":48,"slug":49},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",{"category":51},{"id":52,"icon":34,"name":53,"slug":54},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[56,60],{"type":57,"value":58,"context":59},"cve","CVE-2025-7850","Previously disclosed vulnerability enabling remote code execution",{"type":57,"value":61,"context":59},"CVE-2025-7851"]