Key Findings
- This research, to be presented at Black Hat USA 2026, uncovers 15 new vulnerabilities affecting Zero-Touch Provisioning (ZTP) in TP-Link’s Omada ecosystem.
- Some vulnerabilities extend beyond Omada to other TP-Link products and services, including IP cameras, smart home IoT devices, mobile apps, and cloud accounts.
- Findings include a chain of trust compromise from hard-coded cryptographic keys, sensitive information disclosures, and remote code execution.
- The vulnerabilities fall into five impact categories: remote OS command execution, client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications.
- Combined with two previously disclosed CVEs (CVE-2025-7850 and CVE-2025-7851), these flaws enable concrete attacks that let attackers infiltrate networks through controllers and client devices.
Mitigation Recommendations
- Avoid using the same password across all devices during provisioning.
- Change device credentials and use strong, unique passwords.
- Change TP-Link ID credentials and enable multifactor authentication where available.
- Rotate VPN keys and credentials that may have been exposed.
- Reduce the risk of local man-in-the-middle attacks by implementing appropriate controls, such as 802.1X + NAC, port security, dynamic ARP inspection, wireless client isolation, and network segmentation.
- Adopt a defense-in-depth approach.
- Monitor network activity using intrusion detection and other network security monitoring controls.