Key Findings

  • This research, to be presented at Black Hat USA 2026, uncovers 15 new vulnerabilities affecting Zero-Touch Provisioning (ZTP) in TP-Link’s Omada ecosystem.
  • Some vulnerabilities extend beyond Omada to other TP-Link products and services, including IP cameras, smart home IoT devices, mobile apps, and cloud accounts.
  • Findings include a chain of trust compromise from hard-coded cryptographic keys, sensitive information disclosures, and remote code execution.
  • The vulnerabilities fall into five impact categories: remote OS command execution, client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications.
  • Combined with two previously disclosed CVEs (CVE-2025-7850 and CVE-2025-7851), these flaws enable concrete attacks that let attackers infiltrate networks through controllers and client devices.

Mitigation Recommendations

  • Avoid using the same password across all devices during provisioning.
  • Change device credentials and use strong, unique passwords.
  • Change TP-Link ID credentials and enable multifactor authentication where available.
  • Rotate VPN keys and credentials that may have been exposed.
  • Reduce the risk of local man-in-the-middle attacks by implementing appropriate controls, such as 802.1X + NAC, port security, dynamic ARP inspection, wireless client isolation, and network segmentation.
  • Adopt a defense-in-depth approach.
  • Monitor network activity using intrusion detection and other network security monitoring controls.

This content is password-protected. To view it, please enter the password below.