Key Findings

  • This research, to be presented at Black Hat USA 2026, uncovers 15 new vulnerabilities affecting Zero-Touch Provisioning (ZTP) in TP-Link’s Omada ecosystem.
  • Some vulnerabilities extend beyond Omada to other TP-Link products and services, including IP cameras, smart home IoT devices, mobile apps, and cloud accounts.
  • Findings include a chain of trust compromise from hard-coded cryptographic keys, and sensitive information disclosures, and remote code execution.
  • The vulnerabilities fall into four impact categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications.
  • Combined with two previously disclosed CVEs (CVE-2025-7850 and CVE-2025-7851), these flaws enable concrete attacks that let attackers infiltrate networks through controllers and client devices.

Mitigation Recommendations

  • Avoid using the same password across all devices during provisioning.
  • Change device credentials and use strong, unique passwords.
  • Change TP-Link ID credentials and enable multifactor authentication where available.
  • Rotate VPN keys and credentials that may have been exposed.
  • Reduce the risk of local man-in-the-middle attacks by implementing appropriate controls, such as 802.1X + NAC, port security, dynamic ARP inspection, wireless client isolation, and network segmentation.
  • Adopt a defense-in-depth approach.
  • Monitor network activity using intrusion detection and other network security monitoring controls.

For more than three years, Forescout Research – Vedere Labs has reported on the increasing exploitation of network infrastructure devices, such as routers and firewalls. Previous research, including Sierra:21 and Dray:Break, and observed threat actor activity by the larger research community targeting these devices, focused on individual vulnerabilities that enable remote code execution.

However, the growing use of Zero-Touch Provisioning (ZTP) by IT teams creates opportunities for attacks at a much larger scale. Network vendors offer ZTP ecosystems in which provisioning servers push configurations and updates to client devices, including routers, switches, gateways, and wireless access points. This enables devices to be configured with little or no manual intervention.

In the new “Zero Day Provisioning” research, we present 15 new vulnerabilities affecting ZTP in TP-Link Omada – a network device ecosystem for small and medium businesses – and other devices of the same vendor, including IP cameras, smart home IoT, mobile applications, and cloud accounts. Beyond the individual vulnerabilities on TP-Link, this research highlights how ZTP enables new attack scenarios.

Full details are available in the technical report. Below we summarize the main findings of the research and risk mitigation recommendations.

Brief Introduction to ZTP

Zero touch provisioning allows network administrators to provision a fleet of network devices, such as switches and routers, at scale. When a new ZTP-enabled device is connected to the network using ZTP, it identifies a provisioning server, known as a controller, and receives configuration data from it. This may include network settings, credentials, and pending firmware updates. The controller can then continue to manage the enrolled device and apply subsequent configuration changes.

ZTP enables organizations to deploy new equipment rapidly via central management, significantly reducing operational efforts and costs. However, it depends on a secure chain of trust between controllers and managed devices, as well as on securely designed and implemented network protocols. This creates several potential security risks:

  1. Improved usability can introduce security trade-offs. Zero-touch deployment may rely on pre-shared secrets or other mechanisms that allow controllers and devices to mutually authenticate. Establishing and maintaining this chain of trust securely can be difficult.
  2. Centralized management creates a potential single point of compromise. If an attacker compromises a provisioning server, they may gain access to all the devices it manages, putting entire networks at risk.
  3. There is no universal set of ZTP protocols. Vendors commonly design and implement proprietary protocols, increasing the possibility of security weaknesses in their design or implementation.
  4. ZTP controllers and clients are often highly trusted within the network. Attacks that compromise ZTP-enabled devices or abuse the provisioning protocols may therefore be difficult to detect. These devices may be covered by firewall exceptions and are often used for network administration, making malicious activity less likely to be identified by network intrusion detection systems. In this sense, abusing ZTP can resemble living off the land within network infrastructure.

TP-Link Omada is a ZTP-enabled ecosystem for routers, switches, gateways, and Wi-Fi access points. There are three types of controllers in this ecosystem: cloud-based, dedicated hardware, or software. Here is a deployment example with the cloud-based controller, which can configure devices via the Internet and can be operated via a mobile application:

New Vulnerabilities

We found the 15 new vulnerabilities listed below. The table only shows a short description of each issue, but they are individually detailed in the technical report. TP-link decided not to issue CVE IDs for FSCT-2025-0003, FSCT-2025-0008, FSCT-2025-0011 and FSCT-2025-0014. The vulnerabilities can be grouped into the following impact categories:

  • Client-side code execution through cross-channel scripting
  • Disclosure of sensitive information, including passwords and cryptographic keys
  • Device hijacking and spoofing
  • Compromise of encrypted communications and the underlying chain of trust
Vulnerability Products Description
FSCT-2025-0003 Omada and Festa VPN routers Devices that have not already been adopted can be adopted using only their serial numbers.
CVE-2025-15544 Omada hardware, software, and cloud-based controllers, and potentially other product lines Local and cloud-based controllers transmit site credentials insecurely.
CVE-2025-15627 Omada hardware and software controllers, and potentially other product lines Omada controllers contain a hard-coded private key used to protect communications with client devices when version 1 of the Omada protocol is used.
CVE-2025-15628 Omada hardware and software controllers and potentially other product lines Version 2 of the Omada protocol relies on a hard-coded TLS server certificate and corresponding private key, compromising the chain of trust.
CVE-2025-15629 Omada hardware and software controllers The RC4 key used to encrypt communications between clients and controllers in version 1 of the Omada protocol has insufficient entropy and can be predicted.
FSCT-2025-0008 Omada hardware, software, and cloud-based controllers and potentially other product
lines
During initial device adoption, authentication challenges are signed using default credentials.
CVE-2025-15630 Omada cloud-based controllers and potentially other product lines During cloud adoption, an attacker can exploit a race condition by initiating the handshake before the legitimate device while spoofing only its MAC address. This may expose the initial configuration, including administrator credential hashes and other confidential information.
CVE-2025-9289 Omada hardware, software, and cloud-based controllers The Omada controller web interface is vulnerable to cross-channel scripting because values supplied during device adoption are not properly sanitized.
FSCT-2025-0011 Omada cloud-based controllers Device serial numbers are sequential and predictable. Attackers can use guessed serial numbers to retrieve device MAC addresses and related information through the Omada Cloud API or web interface.
CVE-2025-9290 Omada hardware, software, and cloud-based controllers and potentially other product lines Version 2 of the Omada protocol does not ensure that salt values used in credential authentication are unique or non-empty, allowing attackers to obtain static credential hashes.
CVE-2025-9291 Omada and Festa VPN routers and potentially other devices Omada client devices perform insufficient Common Name checks when validating controller certificates.
FSCT-2025-0014 Omada hardware, software, and cloud-based controllers and potentially other product lines Local and cloud-based controllers allow arbitrary files to be uploaded and later retrieved through unauthenticated and temporary links.
CVE-2025-15631 Omada and Festa VPN routers and potentially other devices Unsalted MD5 hashes of device-management passwords are encrypted using a hard-coded key.
CVE-2025-9292 Omada cloud-based controllers The controller’s Content Security Policy permits connections to CloudFront and Amazon Web Services subdomains.
CVE-2025-9293 TP-Link Android applications:

Tapo 3.11.114
Kasa 3.4.101
Omada 4.24.13
Omada Guard 1.0.14
Tether 4.10.42
Deco 3.9.76
Aginet 2.11.23
tpCamera 3.2.12
WiFi Toolkit 1.4.2
Festa 1.6.9
Wi-Fi Navi 1.4.8
KidShield 1.1.19

The applications perform insufficient certificate validation and rely on the same compromised chain of trust described in CVE-2025-15628.

Impact and Attack Scenarios

TP-Link’s website provides examples of Omada devices used in major residential deployments, large industrial complexes, offices, warehouses, and other environments. Here is a network topology of a real Omada deployment in an industrial estate comprising nine hardware controllers, eight Omada routers/switches, and close to 150 Omada access points:

The full report describes several attack scenarios that would work on a network like this using the new vulnerabilities and two others we previously disclosed against TP-Link devices (CVE-2025-7850 and CVE-2025-7851).

Here, we focus on one scenario, where an attacker positioned outside the victim network wants to gain control over devices in the internal network. The steps are as follows:

  1. The attacker collects the MAC addresses of Omada client devices by enumerating predictable serial numbers via the Omada API or the web dashboard (FSCT-2025-0003 and FSCT-2025-0011) with the goal of finding devices that have not yet been adopted by a cloud controller.
  2. The attacker can ‘impersonate’ a device that is about to be adopted by a controller. They send an initial message to the controller spoofing the client’s MAC address. The attacker can resend this message every 60 seconds to exploit the race condition CVE-2025-15630. The goal is that the controller initially accepts a message sent by the legitimate device, then also accepts the next expected message coming from the attacker.
  3. After the controller responds to the attacker and the fake device enters the Adopt stage, the attacker can successfully authenticate it with the controller using the default credentials (FSCT-2025-0008). The controller will respond with the device configuration, including a cleartext username and an unsalted MD5 hash of the site credentials (CVE-2025-15544) and possibly other sensitive information such as VPN keys.
  4. At the same time, the attacker can inject arbitrary JavaScript code into the web interface of the administrator account using the Cloud controller (CVE-2025-9289). With this the attacker can exfiltrate data, for example, by displaying a fake login dialog to phish the administrator and capture the cloud controller credentials, by additionally leveraging a CORS bypass (CVE-2025-9292).
  5. Once the attacker obtains the admin credentials of a controller, they may log into it and perform actions on the clients already adopted by this controller, such as: configure VPN tunnels that would lead into the internal network and attempt to compromise devices using other vulnerabilities (such as CVE-2025-7850).

We currently observe more than 1,800 Omada controllers accessible online. These appear to be exceptions because deployments like these are not intended to be exposed directly to the Internet. Another way to estimate the number of Omada deployments is via downloads of mobile apps for the Omada ecosystem: TP-Link Omada and Omada Guard have 1.1 million downloads on Google Play.

Other TP-Link mobile applications affected by CVE-2025-15628 and CVE-2025-9293 were downloaded more than 70 million times on Google Play. We estimate that there could be between 3 to 7 million active user accounts.

Many of these applications can be used with the same TP-Link cloud account. This indicates that multiple TP-Link product ecosystems share elements of the same cloud identity and infrastructure. They also rely on the compromised chain of trust described in CVE-2025-15628 and CVE-2025-9293, potentially allowing attackers to impersonate application back-end services or intercept communications between applications and devices.

Beyond Omada and several mobile applications, CVE-2025-15628 also affects the TP-Link VIGI physical surveillance ecosystem. In deployments using a local Video Management System – which operates in a manner similar to a local Omada controller – an attacker may be able to impersonate the controller, intercept surveillance communications, or manipulate data transmitted between the controller and managed devices. Depending on the affected functionality, this could include interference with video feeds.

Mitigation Recommendations

ZTP implementations can contain significant security flaws that threat actors may exploit to conduct attacks at scale. As more vendors implement ZTP and more organizations adopt it, these risks require greater attention.

To mitigate the vulnerabilities, organizations need to patch affected devices and update all affected software, including controllers and mobile applications.

CVEs Official advisory
CVE-2025-9289, CVE-2025-39290 https://support.omadanetworks.com/us/document/114950/
CVE-2025-9292, CVE-2025-9293 https://www.tp-link.com/us/support/faq/4969/
CVE-2025-9291, CVE-2025-15544, CVE-2025-15627, CVE-2025-15628, CVE-2025-15629, CVE-2025-15630, CVE-2025-15631 https://support.omadanetworks.com/us/document/130626/

In addition to applying patches and software updates, we recommend that organizations:

  • Avoid using the same password across all devices during provisioning.
  • Change device credentials and use strong, unique passwords.
  • Change TP-Link ID credentials and enable multifactor authentication where available.
  • Rotate VPN keys and credentials that may have been exposed.
  • Reduce the risk of local MiTM attacks by implementing appropriate controls, such as 802.1X + NAC, port security, Dynamic ARP inspection, wireless client isolation, and network segmentation.
  • Adopt a defense-in-depth approach.
  • Monitor network activity using intrusion detection and other network security monitoring controls.

Recommendations for vendors implementing ZTP protocols are available in the technical report.

Stay on top of the latest threats. Sign up for the Vedere Labs Threat Feed and get the full context in our monthly newsletter.