TP-Link Omada Devices Vulnerable to Remote Code Execution via ZTP Flaws
**TP-Link** has addressed a critical set of 15 vulnerabilities within the zero-touch provisioning (ZTP) mechanism of its **Omada** network devices. These flaws, if chained with previously disclosed command-injection vulnerabilities, could enable remote code execution (RCE), posing a significant risk to small to medium-sized businesses and enterprises relying on **Omada** for their network infrastructure.

Cybersecurity researchers from **Forescoutβs Vedere Labs** have unveiled 15 vulnerabilities impacting the **zero-touch provisioning (ZTP)** functionality across **TP-Link Omada** network devices. These newly discovered flaws, detailed at the **Black Hat USA** security conference, could be exploited in conjunction with existing vulnerabilities to achieve **remote code execution (RCE)**.
**Omada**, **TP-Link's** business networking product line, encompasses a range of devices including Wi-Fi access points, Ethernet switches, internet gateways, and VPN routers. These are widely deployed in small to medium-sized businesses (SMBs) and increasingly in larger enterprise environments.
**ZTP** is a crucial feature for efficient network deployment, allowing IT teams or managed service providers (MSPs) to remotely configure and provision devices without manual on-site intervention.

### Broad Impact Across TP-Link Ecosystem
The implications of **Forescout's** findings extend beyond **Omada** devices. Several of the 15 vulnerabilities also affect other **TP-Link** products and services, including IP cameras, smart home IoT devices, mobile applications, and cloud accounts. The identified issues span a range of critical weaknesses:
* Hard-coded cryptographic keys
* Information disclosure
* Remote code execution
* Device hijacking and spoofing
* Client-side code execution
* Interception or compromise of encrypted communications
According to **Forescout**, attackers could combine these new flaws with two previously disclosed command-injection vulnerabilities, **CVE-2025-7850** and **CVE-2025-7851**, to compromise **Omadaβs** chain of trust and infiltrate networks.
### Detailed Vulnerability Identifiers
**TP-Link's** advisory lists the 15 newly disclosed flaws, with 11 receiving official **CVE** identifiers:
* **CVE-2025-9289** through **CVE-2025-9293**
* **CVE-2025-15544**
* **CVE-2025-15627** through **CVE-2025-15631**
The remaining four findings, though lacking **CVE** numbers, are equally critical. They pertain to device adoption based solely on serial numbers, default credentials during initial adoption, predictable serial numbers, and unauthenticated temporary download links for configuration files.
### Attack Scenario: Compromising the Chain of Trust
**Forescout** illustrated a potential attack scenario where a remote attacker could exploit predictable device serial numbers to obtain **MAC** addresses and identify devices awaiting adoption. By impersonating one of these devices and exploiting a race condition during cloud adoption, an attacker could authenticate using default credentials.
This would force the controller to disclose the device configuration, including cleartext usernames, unsalted **MD5** password hashes, and potentially **VPN** keys. The attacker could also inject **JavaScript** into the controller's administrative interface, enabling phishing attacks to steal administrator cloud-controller credentials.
Once credentials are stolen, the attacker gains the ability to reconfigure managed devices, establish **VPN** tunnels into the internal network, and exploit previously disclosed command-injection flaws to compromise network equipment.

### Affected Products and Recommendations
The vulnerabilities impact a wide array of **Omada** products, including Controllers, Gateways, Switches, Access Points, OLT platforms, Cloud services, and **TP-Link** mobile applications. **Forescout** identified over 1,800 internet-accessible **Omada** controllers, despite these deployments typically not being intended for direct internet exposure.
**TP-Link's** **Omada** and **Omada Guard** Android applications have substantial download figures, with **TP-Link** apps collectively serving millions of active accounts, highlighting the broad attack surface.
Users are strongly advised to take immediate action:
* Visit **TP-Linkβs Omada** [download portal](https://support.omadanetworks.com/en/download/) to acquire and install the latest firmware updates for all affected device models.
* Implement strong, unique administrator credentials for all devices and cloud accounts.
* Enable multi-factor authentication (**MFA**) wherever possible.
* Rotate all secrets (passwords, keys) if a compromise is suspected.
* Update all **TP-Link** mobile applications to their latest versions.
* Actively monitor network traffic for any suspicious activity that could indicate an attempted or successful exploit.