Protect.Computer
NEWS

TP-Link patches 15 flaws letting hackers breach Omada networks

· 1 min read · Network safety Device safety
TP-Link patches 15 flaws letting hackers breach Omada networks

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) system built into its Omada business networking line — the feature that lets IT teams remotely configure switches, access points, and VPN routers without visiting each device on-site. Security researchers at Forescout’s Vedere Labs presented the findings at Black Hat USA, showing that attackers could chain these new flaws with two older command-injection vulnerabilities (CVE-2025-7850 and CVE-2025-7851) to compromise Omada’s trust chain and gain a foothold inside any network managed by these devices.

The 11 CVE-numbered flaws (CVE-2025-9289 through CVE-2025-9293, CVE-2025-15544, and CVE-2025-15627 through CVE-2025-15631) span a wide range of impact categories: hard-coded cryptographic keys, information disclosure, device hijacking and spoofing, client-side code execution, and the ability to intercept encrypted communications. In one attack scenario, a remote attacker with no credentials could enumerate predictable device serial numbers, impersonate a device waiting for adoption, exploit a race condition, and ultimately steal administrator credentials — then reconfigure managed switches and routers, create rogue VPN tunnels into the internal network, and execute arbitrary code. The flaws affect Omada controllers, gateways, switches, access points, OLT platforms, cloud services, and TP-Link mobile applications. Forescout found more than 1,800 Omada controllers directly exposed to the internet, even though TP-Link recommends against that configuration.

How to check if you’re affected

Affected products include Omada Controllers, Gateways, Switches, Access Points, and associated TP-Link mobile applications running firmware versions prior to the latest patched releases. Visit the TP-Link Omada download portal, locate your device model, and install any available firmware update. TP-Link also recommends setting strong, unique administrator credentials, enabling multi-factor authentication (MFA) on the Omada controller, and rotating all secrets if compromise is suspected. Omada devices directly reachable from the internet should be placed behind a firewall immediately regardless of patching status.

Sources

Related reading