LIVE · cybersecurity feed
Live wire
Bypassing AI guardrails is so easy a script kiddie can do itCVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
breach

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]

zeroday.news · 3h ago

TP-Link has addressed 15 vulnerabilities within the zero-touch provisioning (ZTP) mechanism of its Omada networking devices. These flaws, when chained with previously identified vulnerabilities, could lead to remote code execution (RCE) on affected systems. The vulnerabilities were discovered by researchers at Forescout's Vedere Labs, who presented their findings at the Black Hat USA security conference.

Omada is TP-Link's business-focused product line, encompassing Wi-Fi access points, Ethernet and PoE switches, internet gateways, and VPN routers. These devices are commonly deployed in small to medium-sized businesses, though TP-Link also markets them for enterprise use. ZTP facilitates the remote deployment of network devices by allowing IT teams or managed service providers (MSPs) to pre-configure them without requiring on-site manual setup.

Beyond Omada devices, some of the 15 vulnerabilities identified by Forescout also impact other TP-Link products and services, including IP cameras, smart home IoT devices, mobile applications, and cloud accounts. The issues span several categories, including hard-coded cryptographic keys, information disclosure, remote code execution, device hijacking and spoofing, client-side code execution, and the interception or compromise of encrypted communications.

Forescout's analysis indicates that attackers could combine these newly disclosed flaws with two previously known command-injection vulnerabilities, identified as CVE-2025-7850 and CVE-2025-7851, to compromise Omada's chain of trust and infiltrate networks. The vulnerabilities enable concrete attack scenarios that allow attackers to breach networks through both controllers and client devices.

TP-Link's advisory lists 15 newly disclosed flaws. Eleven of these have been assigned CVE identifiers: CVE-2025-9289 through CVE-2025-9293, CVE-2025-15544, and CVE-2025-15627 through CVE-2025-15631. The remaining four findings, which did not receive CVEs, relate to device adoption based solely on serial numbers, default credentials used during initial adoption, predictable serial numbers, and files made available via unauthenticated temporary download links.

One attack scenario described by Forescout involves a remote attacker enumerating predictable device serial numbers to obtain MAC addresses and identify devices awaiting adoption. The attacker could then impersonate one of these devices, exploit a race condition during cloud adoption, and authenticate using default credentials. This process could lead to the controller disclosing the device configuration, including a cleartext username, an unsalted MD5 password hash, and potentially VPN keys.

Further, an attacker could inject JavaScript into the controller's administrative interface to phish an administrator and steal their cloud-controller credentials. With stolen credentials, the attacker could reconfigure managed devices, establish VPN tunnels into the internal network, and exploit previously disclosed command-injection flaws to compromise network equipment.

The vulnerabilities affect a range of Omada products, including Controllers, Gateways, Switches, Access Points, OLT platforms, Cloud services, and TP-Link mobile applications. Forescout reported identifying over 1,800 internet-accessible Omada controllers, despite such deployments typically not being intended for direct exposure to the internet. The Omada and Omada Guard Android applications have accumulated 1.1 million downloads on Google Play, while TP-Link's collective mobile applications serve between 3 and 7 million active accounts.

Users are advised to download the latest firmware images for their specific device models from TP-Link's Omada download portal. Additionally, it is recommended to use strong, unique administrator credentials, enable multi-factor authentication (MFA), rotate all secrets if a compromise is suspected, update mobile applications, and monitor network traffic for any suspicious activity.

breachvulnerabilitypatchcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

OK, Well, There Are Even More AI Agent Hacking Incidents

Rogue AI agents from OpenAI and Anthropic have again been caught trying to disrupt servers and software—and leaving instructions for future bad behavior.

ai

AISI, OpenAI report more ‘unsanctioned’ model hacks

Following similar reports by OpenAI and Anthropic, the UK’s top AI testing lab and a private cybersecurity tester say their models exploited parts of the open internet. The post AISI, OpenAI report more ‘unsanctioned’ model hacks appeared first on CyberScoop.

cloud

Apple battles it out again with the UK over encrypted iCloud access

Apple is fighting another attempt by the UK's Home Office to get a backdoor providing access to encrypted iCloud data.

nation-state

OpenAI: Cambodian scam centers used ChatGPT to lure Indian nationals, conduct investment fraud

A tip from WhatsApp led OpenAI to ban multiple accounts associated with investment scams and human trafficking operations based in Cambodian scam centers.

vulnerability

SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency

Swiss Federal IT Agency FOITT says attackers exploited SharePoint flaws to compromise about 200 accounts. Servers are being rebuilt as investigations continue. Switzerland’s Federal Office for Information Technology and Communications, known as BIT or FOITT, disclosed that unknown attackers had compromised approximately 200 accounts on its on-premises SharePoint servers. The FOITT said the unknown

malware

New XCSSET variant targets macOS devs via compromised Xcode projects

A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. [...]