Executive Summary
In August 2026, TP-Link addressed 15 vulnerabilities in the Zero-Touch Provisioning (ZTP) mechanism of its Omada network devices, as disclosed by Forescout’s Vedere Labs at the Black Hat USA security conference. These flaws, encompassing hard-coded cryptographic keys, information disclosure, remote code execution, and device hijacking, could be exploited to infiltrate networks by compromising Omada’s chain of trust. Notably, attackers could combine these vulnerabilities with previously identified command-injection flaws (CVE-2025-7850 and CVE-2025-7851) to achieve remote code execution. The affected products include Omada Controllers, Gateways, Switches, Access Points, OLT platforms, Cloud services, and TP-Link mobile applications.
This incident underscores the critical importance of securing network infrastructure, especially as routers and switches have become primary threat vectors, surpassing traditional endpoints. Organizations are urged to promptly apply firmware updates, enforce strong authentication measures, and monitor network traffic to mitigate potential exploits stemming from these vulnerabilities.
Why This Matters Now
The exploitation of these vulnerabilities could lead to unauthorized access and control over network devices, posing significant risks to organizational security. Immediate action is required to prevent potential breaches and data exfiltration.
Attack Path Analysis
An attacker exploited predictable device serial numbers to impersonate devices awaiting adoption, gaining unauthorized access. They then escalated privileges by exploiting default credentials and a race condition during cloud adoption. Using the compromised controller, the attacker moved laterally to reconfigure managed devices and establish VPN tunnels into the internal network. The attacker maintained command and control by injecting JavaScript into the administrative interface to steal cloud-controller credentials. Subsequently, they exfiltrated sensitive configuration data, including cleartext usernames, unsalted MD5 password hashes, and VPN keys. Finally, the attacker impacted the network by exploiting command-injection vulnerabilities to compromise network equipment.
Kill Chain Progression
Initial Compromise
Description
Exploited predictable device serial numbers to impersonate devices awaiting adoption, gaining unauthorized access.
Related CVEs
CVE-2025-9289
CVSS 4.7A Cross-Site Scripting (XSS) vulnerability in Omada Controllers allows an attacker to execute arbitrary JavaScript in an administrator's browser, potentially exposing sensitive information.
Affected Products:
TP-Link Systems Inc. Omada Software Controller – < 6.0.0.24
TP-Link Systems Inc. Omada OC200, OC220, OC300, OC400 – < 6.0.0.34
TP-Link Systems Inc. Omada Cloud Controller – < 6.0.0.100
Exploit Status:
no public exploitCVE-2025-9290
CVSS 5.9An authentication weakness in Omada Controllers, Gateways, and Access Points allows an attacker to intercept adoption traffic and forge valid authentication, potentially exposing sensitive information.
Affected Products:
TP-Link Systems Inc. Omada Software Controller – < 6.0.0.24
TP-Link Systems Inc. Omada Cloud Controller – < 6.0.0.100
TP-Link Systems Inc. Omada Hardware Controllers – < 6.0.0.34
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Command and Scripting Interpreter
Abuse Elevation Control Mechanism
Unsecured Credentials
Application Layer Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Network infrastructure vulnerabilities in TP-Link Omada devices enable remote code execution, device hijacking, and network infiltration through zero-touch provisioning flaws.
Computer/Network Security
Critical security fabric gaps exposed through hardcoded keys, encrypted traffic compromise, and lateral movement enabling attackers to breach managed networks.
Telecommunications
ZTP mechanism vulnerabilities in business networking equipment allow device spoofing, VPN key theft, and compromise of encrypted communications infrastructure.
Management Consulting
Managed service providers face client network exposure risks through compromised Omada controllers, enabling attacker infiltration via predictable device adoption processes.
Sources
- TP-Link patches Omada ZTP flaws allowing hackers to breach networkshttps://www.bleepingcomputer.com/news/security/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks/Verified
- Security Advisory on Cross-Site Scripting Vulnerability on Omada Controllers (CVE-2025-9289), and Authentication Weakness on Omada Controllers, Gateways and Access Points (CVE-2025-9290)https://support.omadanetworks.com/us/document/114950/Verified
- NVD - CVE-2025-9289https://nvd.nist.gov/vuln/detail/CVE-2025-9289Verified
- NVD - CVE-2025-9290https://nvd.nist.gov/vuln/detail/CVE-2025-9290Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely constrain the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to impersonate devices may have been limited by enforcing strict identity-based access controls, reducing unauthorized access.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been constrained by enforcing least-privilege access controls, limiting unauthorized privilege escalation.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement may have been limited by segmenting internal network traffic, reducing unauthorized access to managed devices.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain command and control could have been constrained by monitoring administrative interfaces, reducing unauthorized credential theft.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may have been limited by enforcing egress policies, reducing unauthorized data transfers.
The attacker's ability to compromise network equipment could have been constrained by enforcing strict access controls, reducing unauthorized command execution.
Impact at a Glance
Affected Business Functions
- Network Management
- Security Monitoring
Estimated downtime: 3 days
Estimated loss: $50,000
Administrator credentials and network configuration data
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict device-to-device communication and limit lateral movement.
- • Enforce strong, unique administrator credentials and enable multi-factor authentication (MFA) to prevent unauthorized access.
- • Deploy East-West Traffic Security controls to monitor and control internal network traffic, detecting unauthorized movements.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to suspicious activities promptly.
- • Regularly update firmware and software to patch known vulnerabilities and reduce the attack surface.



