Zero-Touch Provisioning Is a Fleet-Scale Attack Vector
We uncovered 15 previously unknown vulnerabilities in TP-Link’s Omada zero-touch provisioning (ZTP) ecosystem — an automated system to configure routers, switches, and access points.
Chained together with disclosed CVEs, the flaws let an attacker impersonate a cloud controller, harvest credentials, and execute code as root without touching a device. The weaknesses extend into other devices and mobile apps in a large, shared cloud ecosystem.
We will present the full findings at Black Hat USA in Las Vegas.
The Scale of Exposure: An Ecosystem Measured in the Billions
TP-Link is one of the world’s largest networking vendors, and Omada is its fastest-growing business line, already deployed across industrial estates, warehouses, and large residential complexes. We currently observe more than 1,800 Omada controllers directly exposed to the internet, despite TP-Link’s own guidance against it. Affected mobile apps have been downloaded over 70 million times combined, pointing to an estimated 3 to 7 million active accounts that touch the vulnerable chain of trust.
1.8K+
Omada controllers already exposed online
70M+
downloads of affected TP-Link apps
3-7M
active accounts estimated at risk
What We Found: Five Ways In, One Root Cause
The 15 vulnerabilities span five impact categories: remote OS command execution, client-side code execution, sensitive information disclosure, device hijacking and spoofing, and compromise of encrypted communications.
At the center is a compromised cryptographic chain of trust — Omada controllers ship with hard-coded certificates and private keys that can be extracted and reused. That single design choice lets a rogue device impersonate a legit controller or a rogue controller impersonate the cloud.
| CVE | Affected vendor | Vulnerability/Impact | Known exploitation? |
|---|---|---|---|
| CVE-2017-3859 | Cisco | Denial of Service | No |
| CVE-2018-0346 | Cisco | Denial of Service | No |
| CVE-2018-0347 | Cisco | Authenticated RCE | No |
| CVE-2022-30525 | Zyxel firewalls | Unauthenticated RCE | Yes, reported by Shadowserver |
| CVE-2023-22955 | AudioCodes VoIP | Missing integrity checks for firmware updates | No |
| CVE-2023-22956 | AudioCodes VoIP | Hard-codedcryptographic keys | No |
| CVE-2023-22957 | AudioCodes VoIP | Hard-codedcryptographic keys | No |
| CVE-2024-47575 | Fortinet FortiManager | RCE | Yes, Mandiant reported that UNC5820 exploited the vulnerability as a zero-day to remotely execute commands, steal FortiGate configurations and credentials, and establish persistence on devices across various industries. |
Why ZTP Is a Blind Spot: Convenience Built On a Single Point of Trust
Zero-touch provisioning lets a controller push configuration to a fleet of devices. That convenience has a cost: compromise the controller, and attackers gain entry into every device it manages. ZTP controllers are highly trusted on the network, so protocol abuse hides in plain sight. And there’s no industry standard, so each vendor has its own.
Here are previously disclosed vulnerabilities affecting components in ZTP environments that interact with provisioning and device management systems. None of these vulnerabilities directly affects a ZTP protocol itself.
From Bug to Breach: 17 Requests a Second Is All It Takes
In our lab, we showed a race-condition attack against Omada Cloud that hijacks devices before an owner ever adopts them, using only a spoofed MAC address and a guessed serial number. Targeting 1,000 unique devices required roughly 17 requests per second.
Once a device is hijacked, default admin/admin credentials hand over cleartext usernames and password hashes for the entire site. Then, attackers can inject JavaScript into the admin’s browser, harvest cloud credentials, and move into the internal network.
One Compromise, Many Ecosystems: the Risk Beyond Omada
The same hard-coded chain of trust is reused across TP-Link’s VIGI surveillance cameras, Festa routers, and the Tapo and Kasa smart home lines — all built on shared protocol design and cloud infrastructure. Because many of these products can be tied to the same TP-Link cloud account, compromising one Omada deployment can open a path into a completely separate VIGI video management system. In practice, that means an attacker who breaches a network’s routers could end up with a view into its security cameras too.
Patch, Rotate, Segment … And See the Findings at Black Hat
Affected organizations should update all controllers, client devices, and mobile apps, rotate site and TP-Link ID credentials, and enable multifactor authentication where available. Segmenting ZTP traffic and monitoring for anomalous adoption activity limits the blast radius even where patches lag.
Vedere Labs will walk through the full research and live attack demos at Black Hat USA in Las Vegas.
How Forescout Helps
Discover. Assess. Control. Govern.
Your journey to Universal Zero Trust Network Access starts with the Forescout Vistaro platform™: the only platform for UZTNA powered by agentic AI. Continuously identify, protect, and ensure the compliance of all assets – IT, IoT, IoMT and OT – regardless of location, automatically. Deliver cloud-native network security intelligence boosted by agentic workflows from the pioneer of traditional NAC.
Shift from reactive firefighting to proactive risk management. Get continuous visibility into what’s actually exposed across every connected asset — managed or not, physical or virtual. The result? Priorities managed. Peace of mind.