Forescout Finds 15 Flaws in TP-Link Omada That Allow Full Fleet Takeover
Forescout's Vedere Labs disclosed 15 vulnerabilities in TP-Link's Omada Zero-Touch Provisioning system on August 4, 2026, tracked across multiple CVEs including CVE-2025-7850 and CVE-2025-9289 through 9293. Attackers can exploit predictable serial numbers and spoofed MAC addresses to win device adoption race conditions at roughly 1,000 devices per 17 requests per second. By chaining default credentials, hard-coded keys, and weak certificate validation, adversaries can hijack cloud controllers, steal site credentials, inject malicious scripts into the admin interface, and execute root commands on managed devices. The flaws also affect related TP-Link product lines including VIGI, Festa, Tapo, and Kasa, which share the same protocol and trust components. Forescout noted approximately 1,800 Omada controllers are currently exposed to the internet, and detection is difficult because the attack traffic closely resembles normal ZTP activity.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in