Cyber Security News

15 TP-Link Omada ZTP Flaws Enable Router Hijacking and Root Code Execution

A set of 15 vulnerabilities in TP-Link’s Omada Zero-Touch Provisioning (ZTP) could enable attacks against enterprise networks, with the findings set to be presented at Black Hat USA 2026.

TP-Link Omada is widely used to manage routers, switches, gateways, and wireless access points from a central controller. ZTP helps administrators deploy large numbers of devices quickly.

When a new device connects, it finds the controller and receives configuration details, credentials, and firmware updates without manual setup. This convenience creates a high-value target.

If attackers can compromise the trust relationship between a controller and its managed devices, they may gain access to an entire fleet rather than a single router.

The newly reported flaws affect Omada cloud, software, and hardware controllers, as well as Omada and Festa VPN routers. Some issues may also extend to TP-Link IP cameras, smart-home products, cloud accounts, and multiple Android applications, including Tapo, Kasa, Deco, Tether, and Omada Guard.

The vulnerabilities fall into four major categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications.

Several flaws involve hard-coded cryptographic keys, predictable serial numbers, weak password-hash protections, insecure certificate validation, and poor authentication during device adoption.

One critical issue, CVE-2025-15628, involves a hard-coded TLS certificate and private key used by version 2 of the Omada protocol. This can undermine the chain of trust between controllers and client devices.

Another issue, CVE-2025-15627, affects version 1 of the protocol through a hard-coded private key. Attackers may use these weaknesses to impersonate trusted systems or intercept protected communications.

Forescout researchers also identified a cloud adoption race condition, tracked as CVE-2025-15630, that could allow attackers to spoof a device’s MAC address during registration and steal configuration data, including administrator credential hashes, site credentials, and VPN keys.

CVE-2025-9289 could allow cross-channel scripting in the controller web interface due to improperly sanitized device-adoption values. This could enable attackers to inject malicious JavaScript into an administrator session, steal credentials through fake login prompts, or extract controller data.

When combined with previously disclosed flaws CVE-2025-7850 and CVE-2025-7851, the issues could support a complete attack chain.

An attacker could identify unadopted devices, impersonate one during provisioning, obtain sensitive controller data, compromise an administrator account, and then use the controller to modify network settings or target managed routers. In some cases, this could lead to root-level code execution on vulnerable devices.

Organizations should apply TP-Link’s available updates for controllers, devices, and mobile applications. Administrators should avoid shared provisioning passwords, use strong unique credentials, enable multifactor authentication for TP-Link IDs, and rotate VPN credentials that may have been exposed.

Network defenders should also limit local man-in-the-middle risks through 802.1X, network access control, port security, Dynamic ARP Inspection, wireless client isolation, and segmentation.

Continuous intrusion detection and monitoring are important because compromised provisioning systems can appear to be legitimate network management activity.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

7 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

12 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

17 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

23 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

34 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago