Multiple Vulnerabilities Found in TP-Link Omada Products

Multiple Vulnerabilities Found in TP-Link Omada Products

First seen 5 Aug 2026, 12:55 UTC HkcertFeeds2.Feedburnersupport.omadanetworks.comcve.mitre.org 89% similarity 57.8

Article Content

Browse articles
ThreatCluster

Forescout's Vedere Labs identified multiple vulnerabilities in TP-Link Omada products, including security restriction bypass and sensitive information disclosure. Attackers can exploit these vulnerabilities using a guessed serial number to retrieve device MAC addresses and models from the Omada cloud service. Specifically, serials beginning with 22460J500 and 224608100 correspond to ER605 and ER7206 routers, respectively. The vulnerabilities allow for potential spoofing and unauthorized access to sensitive information. Users are advised to apply the fixes issued by TP-Link to mitigate these risks. The vulnerabilities affect a range of Omada products, posing a significant threat to users' network security.

Key Points: • Multiple vulnerabilities in TP-Link Omada products allow for sensitive information disclosure. • Attackers can exploit these vulnerabilities using guessed serial numbers to access device details. • Users are urged to apply vendor-issued patches to protect against potential exploits.

ThreatCluster AI How this analysis works

Timeline

2026-08-05
Vulnerabilities disclosed by Forescout
Forescout's Vedere Labs revealed multiple vulnerabilities in TP-Link Omada products, affecting device security.
Feeds2.Feedburner
2026-08-05
Security bulletin issued by HKCERT
HKCERT published a security bulletin detailing the vulnerabilities and advising users to apply fixes.
Hkcert

Community

Browse all →

Tracked Entities in This Story