FORESCOUT researchers disclosed 15 new vulnerabilities in TP-Link's Omada networking system's zero-touch provisioning (ZTP) protocols, potentially allowing attackers to compromise entire networks. The security flaws include hardcoded keys, poor encryption practices, and weak credential management. Among the vulnerabilities, 11 were assigned CVEs, while TP-Link deemed four as low severity. By leveraging these vulnerabilities, hackers can gain administrative access to cloud controllers and hijack devices.
Although TP-Link has issued patches for some issues, others may not be addressed until 2026. The findings will be presented at the upcoming Black Hat conference.