TP-Link has addressed 15 vulnerabilities within the zero-touch provisioning (ZTP) mechanism of its Omada networking devices. These flaws, when chained with previously identified vulnerabilities, could lead to remote code execution (RCE) on affected systems. The vulnerabilities were discovered by researchers at Forescout's Vedere Labs, who presented their findings at the Black Hat USA security conference.
Omada is TP-Link's business-focused product line, encompassing Wi-Fi access points, Ethernet and PoE switches, internet gateways, and VPN routers. These devices are commonly deployed in small to medium-sized businesses, though TP-Link also markets them for enterprise use. ZTP facilitates the remote deployment of network devices by allowing IT teams or managed service providers (MSPs) to pre-configure them without requiring on-site manual setup.
Beyond Omada devices, some of the 15 vulnerabilities identified by Forescout also impact other TP-Link products and services, including IP cameras, smart home IoT devices, mobile applications, and cloud accounts. The issues span several categories, including hard-coded cryptographic keys, information disclosure, remote code execution, device hijacking and spoofing, client-side code execution, and the interception or compromise of encrypted communications.
Forescout's analysis indicates that attackers could combine these newly disclosed flaws with two previously known command-injection vulnerabilities, identified as CVE-2025-7850 and CVE-2025-7851, to compromise Omada's chain of trust and infiltrate networks. The vulnerabilities enable concrete attack scenarios that allow attackers to breach networks through both controllers and client devices.
TP-Link's advisory lists 15 newly disclosed flaws. Eleven of these have been assigned CVE identifiers: CVE-2025-9289 through CVE-2025-9293, CVE-2025-15544, and CVE-2025-15627 through CVE-2025-15631. The remaining four findings, which did not receive CVEs, relate to device adoption based solely on serial numbers, default credentials used during initial adoption, predictable serial numbers, and files made available via unauthenticated temporary download links.
One attack scenario described by Forescout involves a remote attacker enumerating predictable device serial numbers to obtain MAC addresses and identify devices awaiting adoption. The attacker could then impersonate one of these devices, exploit a race condition during cloud adoption, and authenticate using default credentials. This process could lead to the controller disclosing the device configuration, including a cleartext username, an unsalted MD5 password hash, and potentially VPN keys.
Further, an attacker could inject JavaScript into the controller's administrative interface to phish an administrator and steal their cloud-controller credentials. With stolen credentials, the attacker could reconfigure managed devices, establish VPN tunnels into the internal network, and exploit previously disclosed command-injection flaws to compromise network equipment.
The vulnerabilities affect a range of Omada products, including Controllers, Gateways, Switches, Access Points, OLT platforms, Cloud services, and TP-Link mobile applications. Forescout reported identifying over 1,800 internet-accessible Omada controllers, despite such deployments typically not being intended for direct exposure to the internet. The Omada and Omada Guard Android applications have accumulated 1.1 million downloads on Google Play, while TP-Link's collective mobile applications serve between 3 and 7 million active accounts.
Users are advised to download the latest firmware images for their specific device models from TP-Link's Omada download portal. Additionally, it is recommended to use strong, unique administrator credentials, enable multi-factor authentication (MFA), rotate all secrets if a compromise is suspected, update mobile applications, and monitor network traffic for any suspicious activity.






