Critical RCE in TP-Link Omada ER605 VPN Routers Exposes Hotel Guests
Key Takeaways A critical vulnerability has been identified in TP-Link Omada ER605 VPN routers, enabling remote code execution (RCE). This flaw, tracked as CVE-2024-5035 with a CVSS score of 9.8,...
Key Takeaways
- A critical vulnerability has been identified in TP-Link Omada ER605 VPN routers, enabling remote code execution (RCE).
- This flaw, tracked as CVE-2024-5035 with a CVSS score of 9.8, could allow attackers to hijack hotel Wi-Fi gateways.
- Compromised gateways can silently redirect all guest traffic to malicious servers, facilitating credential harvesting and session hijacking.
- The attack leverages DNS poisoning and, in some cases, Web Proxy Auto-Discovery (WPAD) abuse.
- A patch is available, and immediate updates are crucial for affected organizations and hospitality providers.
TP-Link Omada ER605 VPN Routers Vulnerable to Critical RCE, Exposing Hotel Guests to DNS Poisoning
A severe remote code execution (RCE) vulnerability, identified as CVE-2024-5035, has been discovered in TP-Link Omada ER605 VPN routers. This flaw, boasting a critical CVSS score of 9.8, presents a significant risk, particularly for environments like hotels and conference centers that rely on these devices for guest Wi-Fi. A successful exploit could enable attackers to gain administrative control over the routers, subsequently redirecting all guest internet traffic to malicious infrastructure without their knowledge. This sophisticated attack vector bypasses traditional phishing and malware detection, posing a direct threat to corporate accounts and sensitive information.
Table Of Content
The core of this threat lies in the inherent trust users place in public Wi-Fi gateways. When travelers connect to hotel or conference networks, they assume the gateway will handle their internet requests securely. However, this vulnerability allows threat actors to exploit that trust by silently rerouting web requests through their controlled servers. This technique, described in detail in a report by Reliaquest, involves poisoning DNS responses at captive portal appliances to harvest Microsoft 365 credentials from employees on the go. This campaign has been observed in various cities across the United States, India, and Saudi Arabia, impacting guests from critical sectors such as finance, legal, healthcare, energy, and retail.
The Attack Mechanism: DNS Poisoning and Impersonation
According to Reliaquest’s Threat Research team, the tactics employed bear a resemblance to those used by APT28 (also known as Fancy Bear and Forest Blizzard), a group previously known for targeting SOHO routers by manipulating DNS settings. In this latest campaign, attackers alter DNS resolution at the gateway, causing users’ requests for legitimate domains to be silently resolved to attacker-controlled IP addresses. This redirection leads users to sophisticated, lookalike Microsoft login pages designed to capture credentials or exploit Microsoft’s device code flow.
The impact of such an attack is extensive and insidious. A single compromised captive portal appliance effectively becomes a man-in-the-middle for every device connecting to the network. This means that an employee simply opening a browser and encountering a seemingly legitimate Microsoft sign-in page could unknowingly expose their credentials. There is no need for a phishing email or a malicious download, making the attack highly effective and difficult for an average user to detect.

Reliaquest has identified several attacker-registered domains, including m365-owa.com, owa-ms365.com, ms365-device.com, and ms365-live.com, hosted on IP addresses 31.57.243.154 and 104.194.159.150. These domains are used to impersonate Microsoft services, enabling the theft of credentials or the abuse of Microsoft’s device code flow. This latter technique allows attackers to obtain OAuth tokens, granting them multi-factor authentication (MFA)-satisfied access to Microsoft 365 without directly compromising passwords, turning legitimate login prompts into silent session hijacks.
Furthermore, approximately one-third of the observed attacks involved the abuse of Web Proxy Auto-Discovery (WPAD). This allows Windows devices to fetch a malicious proxy auto-configuration file, silently routing additional traffic through attacker-controlled proxies. This method can make the malicious activity appear as normal HTTPS traffic in logs, making detection challenging for organizations without rigorous proxy authentication record reviews.
What You Should Do
- Apply Patches Immediately: TP-Link has released firmware updates to address CVE-2024-5035. Organizations using Omada ER605 VPN routers must apply these patches without delay.
- Implement Always-On VPN with Full Tunneling: Configure corporate VPNs to operate in an “always-on” full-tunnel mode. This ensures all DNS requests are routed through trusted corporate resolvers, bypassing potentially compromised public Wi-Fi gateways. Audit for split tunneling exceptions that could allow DNS or authentication traffic to bypass the VPN.
- Enforce Strict Encrypted DNS: Configure endpoint DNS encryption tools to operate in strict mode (e.g., DNS over HTTPS or DNS over TLS). Avoid opportunistic modes that allow plaintext fallback, as this creates a vulnerability for DNS poisoning.
- Disable WPAD Where Unnecessary: If Web Proxy Auto-Discovery (WPAD) is not essential for your organization, disable it. If it must remain enabled, restrict proxy auto-configuration file retrieval to approved internal hosts only.
- Educate Employees on URL and Certificate Verification: Train employees to meticulously verify URLs and SSL/TLS certificates before entering any credentials, especially when connecting to public Wi-Fi networks in hotels, airports, or conference centers.
- Restrict Microsoft Device Code Authentication Flow: Utilize Conditional Access policies in Microsoft Entra ID to block the device code authentication flow for most users. This flow has limited legitimate uses for typical users and, if abused, can provide attackers with MFA-satisfied access.
- Monitor for Indicators of Compromise (IoCs): Implement continuous monitoring for the following IoCs in your network logs:
Indicators of Compromise (IoCs):-
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.