Bleepingcomputer TP-Link Omada Vulnerabilities Exposed at Black Hat 2026
Article Content
- •TP-Link patched 15 vulnerabilities in its Omada network devices affecting ZTP.
- •Exploits could lead to remote code execution and network compromise.
- •Customers are urged to apply patches and rotate credentials immediately.
TP-Link has patched 15 vulnerabilities in its Omada network devices, particularly affecting the Zero-Touch Provisioning (ZTP) mechanism. Discovered by Forescout's Vedere Labs, these flaws could be exploited to achieve remote code execution (RCE) and compromise entire networks. The vulnerabilities include hard-coded cryptographic keys and issues with device onboarding that could allow attackers to impersonate devices and gain unauthorized access. The flaws are particularly critical as they can be chained with previously disclosed vulnerabilities (CVE-2025-7850 and CVE-2025-7851) to escalate attacks. TP-Link has released security advisories and updates, urging customers to apply patches and rotate credentials. Currently, there are no indications that these vulnerabilities are being actively exploited. Affected systems include various TP-Link products, including IP cameras and smart IoT devices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (16)
Following this threat?
Track CVE-2025-7850 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…