15 TP-Link Omada ZTP Flaws Enable Router Hijacking and Root Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A set of 15 vulnerabilities in TP-Link’s Omada Zero-Touch Provisioning (ZTP) could enable attacks against enterprise networks, with the findings set to be presented at Black Hat USA 2026.

TP-Link Omada is widely used to manage routers, switches, gateways, and wireless access points from a central controller. ZTP helps administrators deploy large numbers of devices quickly.

When a new device connects, it finds the controller and receives configuration details, credentials, and firmware updates without manual setup. This convenience creates a high-value target.

If attackers can compromise the trust relationship between a controller and its managed devices, they may gain access to an entire fleet rather than a single router.

The newly reported flaws affect Omada cloud, software, and hardware controllers, as well as Omada and Festa VPN routers. Some issues may also extend to TP-Link IP cameras, smart-home products, cloud accounts, and multiple Android applications, including Tapo, Kasa, Deco, Tether, and Omada Guard.

The vulnerabilities fall into four major categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications.

TP-Link Omada ZTP Flaws

Several flaws involve hard-coded cryptographic keys, predictable serial numbers, weak password-hash protections, insecure certificate validation, and poor authentication during device adoption.

One critical issue, CVE-2025-15628, involves a hard-coded TLS certificate and private key used by version 2 of the Omada protocol. This can undermine the chain of trust between controllers and client devices.

Another issue, CVE-2025-15627, affects version 1 of the protocol through a hard-coded private key. Attackers may use these weaknesses to impersonate trusted systems or intercept protected communications.

Forescout researchers also identified a cloud adoption race condition, tracked as CVE-2025-15630, that could allow attackers to spoof a device’s MAC address during registration and steal configuration data, including administrator credential hashes, site credentials, and VPN keys.

CVE-2025-9289 could allow cross-channel scripting in the controller web interface due to improperly sanitized device-adoption values. This could enable attackers to inject malicious JavaScript into an administrator session, steal credentials through fake login prompts, or extract controller data.

When combined with previously disclosed flaws CVE-2025-7850 and CVE-2025-7851, the issues could support a complete attack chain.

An attacker could identify unadopted devices, impersonate one during provisioning, obtain sensitive controller data, compromise an administrator account, and then use the controller to modify network settings or target managed routers. In some cases, this could lead to root-level code execution on vulnerable devices.

Organizations should apply TP-Link’s available updates for controllers, devices, and mobile applications. Administrators should avoid shared provisioning passwords, use strong unique credentials, enable multifactor authentication for TP-Link IDs, and rotate VPN credentials that may have been exposed.

Network defenders should also limit local man-in-the-middle risks through 802.1X, network access control, port security, Dynamic ARP Inspection, wireless client isolation, and segmentation.

Continuous intrusion detection and monitoring are important because compromised provisioning systems can appear to be legitimate network management activity.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.