“The vulnerabilities fall into four impact categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications,” Forescout’s Vedere Labs explained.
What Forescout found and where it was disclosed
Forescout’s Vedere Labs disclosed 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism used by TP-Link’s Omada line and published full technical details at the Black Hat USA security conference earlier today. TP-Link has issued patches addressing the flaws.
Omada covers TP-Link’s business networking products including Wi‑Fi access points, Ethernet and PoE switches, internet gateways, VPN routers and OLT platforms, typically used by small- to medium-sized businesses and in pro-grade enterprise deployments. ZTP is the remote deployment facility that lets IT teams or managed service providers (MSPs) provision devices without on-site manual configuration; the newly reported flaws target that mechanism.
CVE identifiers and additional untracked findings
TP-Link’s advisory and Forescout’s disclosure list 11 tracked CVEs among the 15 issues:
- CVE-2025-9289 through CVE-2025-9293
- CVE-2025-15544
- CVE-2025-15627 through CVE-2025-15631
The remaining four findings were not assigned tracking numbers. Those untracked issues concern: device adoption based only on knowing the serial number; the use of default credentials during initial adoption; predictable serial numbers; and files exposed via unauthenticated temporary download links.

Your scanner finds 4,000 vulns. Which 12 matter?
Nubivance is a Rapid7 Registered Partner delivering vulnerability management as a service - scanning, risk-based prioritization, and remediation follow-through across IT and OT.
Fix the backlog →How attackers could chain the flaws to breach networks
Forescout warns the ZTP issues can be combined with two earlier command-injection vulnerabilities (CVE-2025-7850 and CVE-2025-7851) to attack Omada’s chain of trust and move from exposed controllers and client devices into internal networks. The researchers mapped explicit abuse paths.
One described scenario begins with a remote attacker enumerating predictable device serial numbers to obtain MAC addresses and identify devices that are awaiting adoption. The attacker then impersonates a device, exploits a race condition in cloud adoption, and authenticates using default credentials. Successful adoption can cause an Omada controller to disclose device configuration containing a cleartext username, an unsalted MD5 password hash, and potentially VPN keys.
Forescout further demonstrated client-side attack vectors: injecting JavaScript into the controller’s administrative interface to phish an administrator and steal cloud-controller credentials. With those credentials in hand, an attacker could reconfigure managed devices, create VPN tunnels into the internal network, and then leverage the previously disclosed command-injection CVEs to execute code on network equipment.
Which products, services and user populations are affected
Forescout says the flaws touch a broad set of Omada components: Controllers, Gateways, Switches, Access Points, OLT platforms, Cloud services, and TP‑Link mobile applications. Some of the 15 flaws also impact other TP‑Link products and services such as IP cameras, smart home IoT devices, mobile applications, and cloud accounts.
Forescout reports discovering more than 1,800 internet-accessible Omada controllers — deployments that the researchers note are generally not intended for direct exposure to the public internet. On the mobile side, the reporting states “Omada and Omada Guard have 1.1 downloads on Google Play,” and that TP‑Link apps collectively have “3 to 7 million active accounts.”
What administrators, IT teams and MSPs should do now
- Obtain and apply the updated firmware images for each device model from TP‑Link’s Omada download portal.
- Use strong, unique administrator credentials and enable multi‑factor authentication (MFA) where available.
- Rotate all secrets when compromise is suspected and update TP‑Link mobile applications.
- Monitor network traffic for suspicious activity and watch for indicators tied to the disclosed attack patterns (unauthorized device adoption, unexpected controller configuration disclosures, or anomalous VPN tunnel creation).
TP‑Link has issued fixes; Forescout has released technical details at Black Hat USA. The disclosure ties a chain of seemingly small weaknesses — predictable serials, default adoption credentials, unsalted hashes, and client-side injection — into a concrete path that can expose internal networks when controllers are reachable from the internet. For administrators, the imperative is immediate: patch, enforce strong credentials and MFA, rotate secrets if compromise is possible, and treat internet‑exposed controllers as high‑risk until verified safe.
Read the original report: https://www.bleepingcomputer.com/news/security/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks/




