LAS VEGAS —Researchers have found fifteen previously unknown vulnerabilities that affect zero-touch provisioning in TP-Link Omada, which is widely used to provision network devices from a central location, according to a report by Forescout Research - Vedere Labs.
Small to medium-sized companies use the technology to rapidly set up routers and firewalls, which in some cases involves thousands of devices. The technology helps companies save considerable costs when deploying network devices, but it also offers attackers wide access to a lot of systems.
The research, presented Wednesday at the Black Hat USA conference in Las Vegas, shows that attackers can chain together vulnerabilities with previously disclosed flaws and infiltrate networks.
“The largest risk is that the Omada provisioning and management protocols can be used for initial access and lateral movement by the attackers,” Principal Security Researcher Stanislav Dashevskyi and Senior Security Researcher Francesco La Spina told Cybersecurity Dive via email.
They said traditional detection systems may have a hard time detecting such an attack because it comes from the “trusted perimeter.”
High risk menu
The newly discovered vulnerabilities pose a serious risk to users, and are grouped in four specifics areas:
- Client-side code execution through cross-channel scripting
- Disclosure of sensitive information, such as passwords and cryptographic keys
- Device hijacking and spoofing
- Compromising encrypted communications as well as the underlying chain of trust
The previously disclosed flaws include a command-injection vulnerability, tracked as CVE-2025-7850 and CVE-2025-7851, which allows an attacker to gain root shell access on the underlying operating system.
TP-Link released a security advisory on Monday to address the vulnerabilities. The company said patches and mitigations were released in multiple stages when the flaws were verified and addressed, as part of a disclosure process coordinated with Forescout.
The company noted that a successful attack generally required chaining multiple vulnerabilities together, rather than exploiting an isolated flaw.
Omada devices are deployed in a variety of work environments, including warehouses, industrial complexes, offices and are also used in residential deployments. Researchers found about 1,800 Omada controllers were visible online, and pointed out that these devices are not supposed to be exposed to the open internet.
Beyond routers and firewalls, the vulnerabilities are also found in other devices, including IP cameras, smart home IoT, mobile applications and cloud accounts.
Researchers are not aware of any recent attacks exploiting the flaws, but they said botnets are known to exploit similar flaws and said it was a matter of time before these vulnerabilities faced such a threat.
Users should patch these flaws and update any affected software to the latest versions.
Other steps to mitigate potential attacks include rotating passwords, not using the same password across multiple devices, rotating any VPN keys that might have been exposed and changing TP-Link ID credentials. Users should also enable multifactor authentication.