TP-Link Omada Vulnerabilities Exposed at Black Hat 2026

TP-Link Omada Vulnerabilities Exposed at Black Hat 2026

First seen 4 Aug 2026, 23:27 UTC BleepingcomputerHeise.DeGbhackersCybersecuritynewsDarkreading+9 87% similarity 70.5

Article Content

Browse articles
ThreatCluster

TP-Link has patched 15 vulnerabilities in its Omada network devices, particularly affecting the Zero-Touch Provisioning (ZTP) mechanism. Discovered by Forescout's Vedere Labs, these flaws could be exploited to achieve remote code execution (RCE) and compromise entire networks. The vulnerabilities include hard-coded cryptographic keys and issues with device onboarding that could allow attackers to impersonate devices and gain unauthorized access. The flaws are particularly critical as they can be chained with previously disclosed vulnerabilities (CVE-2025-7850 and CVE-2025-7851) to escalate attacks. TP-Link has released security advisories and updates, urging customers to apply patches and rotate credentials. Currently, there are no indications that these vulnerabilities are being actively exploited. Affected systems include various TP-Link products, including IP cameras and smart IoT devices.

Key Points: • TP-Link patched 15 vulnerabilities in its Omada network devices affecting ZTP. • Exploits could lead to remote code execution and network compromise. • Customers are urged to apply patches and rotate credentials immediately.

ThreatCluster AI How this analysis works

Timeline

2025-03-14
CVE-2025-1528 published
A hardcoded certificate vulnerability was disclosed affecting TP-Link devices.
Heise.De
2025-10-21
CVE-2025-7850 and CVE-2025-7851 published
Two critical vulnerabilities allowing remote code execution were published.
Bleepingcomputer
2026-01-22
CVE-2025-9289 and CVE-2025-9290 published
Additional vulnerabilities affecting TP-Link products were disclosed.
Bleepingcomputer
2026-02-13
CVE-2025-9292 and CVE-2025-9293 published
Further vulnerabilities impacting TP-Link devices were disclosed.
Bleepingcomputer
2026-08-03
CVE-2025-15627 published
A new vulnerability related to hard-coded cryptographic keys was disclosed.
support.omadanetworks.com
2026-08-04
Vulnerabilities presented at Black Hat USA 2026
Forescout researchers presented findings on vulnerabilities affecting TP-Link's Omada ecosystem.
Bleepingcomputer
2026-08-05
TP-Link issues security advisory
TP-Link released an advisory detailing vulnerabilities and urging customers to apply patches.
support.omadanetworks.com

Community

Browse all →

Tracked Entities in This Story