Zero-Touch Provisioning Is a Fleet-Scale Attack Vector

We uncovered 15 previously unknown vulnerabilities in TP-Link’s Omada zero-touch provisioning (ZTP) ecosystem — an automated system to configure routers, switches, and access points.

Chained together with disclosed CVEs, the flaws let an attacker impersonate a cloud controller, harvest credentials, and execute code as root without touching a device. The weaknesses extend into other devices and mobile apps in a large, shared cloud ecosystem.

We will present the full findings at Black Hat USA in Las Vegas.

READ THE FULL REPORT

The Scale of Exposure: An Ecosystem Measured in the Billions

TP-Link is one of the world’s largest networking vendors, and Omada is its fastest-growing business line, already deployed across industrial estates, warehouses, and large residential complexes. We currently observe more than 1,800 Omada controllers directly exposed to the internet, despite TP-Link’s own guidance against it. Affected mobile apps have been downloaded over 70 million times combined, pointing to an estimated 3 to 7 million active accounts that touch the vulnerable chain of trust.

1.8K+

Omada controllers already exposed online

70M+

downloads of affected TP-Link apps

3-7M

active accounts estimated at risk

What We Found: Five Ways In, One Root Cause

The 15 vulnerabilities span five impact categories: remote OS command execution, client-side code execution, sensitive information disclosure, device hijacking and spoofing, and compromise of encrypted communications.

At the center is a compromised cryptographic chain of trust — Omada controllers ship with hard-coded certificates and private keys that can be extracted and reused. That single design choice lets a rogue device impersonate a legit controller or a rogue controller impersonate the cloud.

CVE Affected vendor Vulnerability/Impact Known exploitation?
CVE-2017-3859 Cisco Denial of Service No
CVE-2018-0346 Cisco Denial of Service No
CVE-2018-0347 Cisco Authenticated RCE No
CVE-2022-30525 Zyxel firewalls Unauthenticated RCE Yes, reported by Shadowserver
CVE-2023-22955 AudioCodes VoIP Missing integrity checks for firmware updates No
CVE-2023-22956 AudioCodes VoIP Hard-codedcryptographic keys No
CVE-2023-22957 AudioCodes VoIP Hard-codedcryptographic keys No
CVE-2024-47575 Fortinet FortiManager RCE Yes, Mandiant reported that UNC5820 exploited the vulnerability as a zero-day to remotely execute commands, steal FortiGate configurations and credentials, and establish persistence on devices across various industries.

Why ZTP Is a Blind Spot: Convenience Built On a Single Point of Trust

Zero-touch provisioning lets a controller push configuration to a fleet of devices. That convenience has a cost: compromise the controller, and attackers gain entry into every device it manages. ZTP controllers are highly trusted on the network, so protocol abuse hides in plain sight. And there’s no industry standard, so each vendor has its own.

Here are previously disclosed vulnerabilities affecting components in ZTP environments that interact with provisioning and device management systems. None of these vulnerabilities directly affects a ZTP protocol itself.

From Bug to Breach: 17 Requests a Second Is All It Takes

In our lab, we showed a race-condition attack against Omada Cloud that hijacks devices before an owner ever adopts them, using only a spoofed MAC address and a guessed serial number. Targeting 1,000 unique devices required roughly 17 requests per second.

Once a device is hijacked, default admin/admin credentials hand over cleartext usernames and password hashes for the entire site. Then, attackers can inject JavaScript into the admin’s browser, harvest cloud credentials, and move into the internal network.

One Compromise, Many Ecosystems: the Risk Beyond Omada

The same hard-coded chain of trust is reused across TP-Link’s VIGI surveillance cameras, Festa routers, and the Tapo and Kasa smart home lines — all built on shared protocol design and cloud infrastructure. Because many of these products can be tied to the same TP-Link cloud account, compromising one Omada deployment can open a path into a completely separate VIGI video management system. In practice, that means an attacker who breaches a network’s routers could end up with a view into its security cameras too.

Patch, Rotate, Segment … And See the Findings at Black Hat

Affected organizations should update all controllers, client devices, and mobile apps, rotate site and TP-Link ID credentials, and enable multifactor authentication where available. Segmenting ZTP traffic and monitoring for anomalous adoption activity limits the blast radius even where patches lag.

Vedere Labs will walk through the full research and live attack demos at Black Hat USA in Las Vegas.

DOWNLOAD THE FULL REPORT

See the Research, Share the Presentation

Vedere Labs shares an overview of the research in a presentation format for you and your security team to use and share. Get all the details of this zero-touch provisioning research, key findings, and our recommendations for mitigating risk.

How Forescout Helps

Discover. Assess. Control. Govern.

Your journey to Universal Zero Trust Network Access starts with the Forescout Vistaro platform™: the only platform for UZTNA powered by agentic AI. Continuously identify, protect, and ensure the compliance of all assets – IT, IoT, IoMT and OT – regardless of location, automatically. Deliver cloud-native network security intelligence boosted by agentic workflows from the pioneer of traditional NAC.

Shift from reactive firefighting to proactive risk management. Get continuous visibility into what’s actually exposed across every connected asset — managed or not, physical or virtual. The result? Priorities managed. Peace of mind.

See the Platform
Demo RequestForescout PlatformTop of Page