Critical TP-Link Omada ZTP Flaws Let Attackers Hijack Routers, Execute Root Code
Key Takeaways Fifteen critical vulnerabilities have been discovered in TP-Link’s Omada Zero-Touch Provisioning (ZTP) system, impacting enterprise networks. These flaws could enable attackers to...
Key Takeaways
- Fifteen critical vulnerabilities have been discovered in TP-Link’s Omada Zero-Touch Provisioning (ZTP) system, impacting enterprise networks.
- These flaws could enable attackers to hijack routers, execute root-level code, and compromise sensitive network data across a range of TP-Link Omada and Festa VPN devices, as well as potentially other TP-Link products.
- The vulnerabilities stem from issues like hard-coded cryptographic keys, weak authentication, and insecure certificate validation, allowing for device spoofing, information disclosure, and client-side code execution.
- TP-Link has released updates, and organizations are urged to apply patches immediately and implement robust network security measures.
Major Vulnerabilities Uncovered in TP-Link Omada ZTP, Threatening Enterprise Networks
A comprehensive set of fifteen vulnerabilities impacting TP-Link’s Omada Zero-Touch Provisioning (ZTP) system has been revealed, posing significant risks to enterprise networks. These critical flaws, slated for detailed presentation at Black Hat USA 2026, could allow attackers to gain deep access to managed network infrastructure.
Table Of Content
TP-Link Omada is a widely adopted platform for centralized management of various network components, including routers, switches, gateways, and wireless access points. Its ZTP feature is designed to streamline the deployment of numerous devices by automating configuration, credential distribution, and firmware updates upon initial connection. While convenient, this automation creates a high-value target for adversaries seeking to compromise an entire fleet of devices rather than individual units.
Successful exploitation of these vulnerabilities could undermine the fundamental trust relationship between an Omada controller and its managed devices. This could grant attackers broad access to the network, impacting not only Omada cloud, software, and hardware controllers but also Omada and Festa VPN routers. Furthermore, the researchers suggest that some of these issues might extend to other TP-Link products, including IP cameras, smart-home devices, cloud accounts, and various Android applications such as Tapo, Kasa, Deco, Tether, and Omada Guard.
Categorization of Flaws and Technical Details
The discovered vulnerabilities are broadly categorized into four key areas: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications. Several specific weaknesses contribute to these categories, including the use of hard-coded cryptographic keys, predictable serial numbers, inadequate password-hash protections, insecure certificate validation processes, and insufficient authentication during device adoption.
One critical vulnerability, identified as CVE-2025-15628, involves a hard-coded TLS certificate and private key used in version 2 of the Omada protocol. This flaw directly compromises the chain of trust between controllers and client devices, making them susceptible to various attacks. Similarly, CVE-2025-15627 affects version 1 of the protocol through another hard-coded private key. Attackers could leverage these weaknesses to impersonate legitimate systems or intercept sensitive, encrypted communications.
Forescout researchers also identified CVE-2025-15630, a cloud adoption race condition. This vulnerability could enable an attacker to spoof a device’s MAC address during the registration process, subsequently stealing critical configuration data. This includes administrator credential hashes, site credentials, and VPN keys.
Another significant flaw, CVE-2025-9289, describes a cross-site scripting (XSS) vulnerability within the controller’s web interface. This is due to improper sanitization of device-adoption values, which could allow attackers to inject malicious JavaScript into an administrator’s session. Such an exploit could lead to credential theft via fake login prompts or the extraction of sensitive data directly from the controller.
Potential Attack Chains and Root Code Execution
When combined with previously disclosed vulnerabilities, specifically CVE-2025-7850 and CVE-2025-7851, the newly identified flaws could facilitate a complete and devastating attack chain. An attacker could initially identify unadopted devices on a network, then impersonate one during the provisioning phase. This could lead to the acquisition of sensitive controller data, ultimately compromising an administrator account. With control over the administrator account, the attacker could then manipulate network settings or directly target managed routers, potentially achieving root-level code execution on vulnerable devices.
What You Should Do
- Apply Updates Immediately: Organizations must prioritize applying all available updates released by TP-Link for their Omada controllers (cloud, software, hardware), network devices, and associated mobile applications.
- Strengthen Authentication: Avoid using shared provisioning passwords. Implement strong, unique credentials for all network devices and administrator accounts. Enable multi-factor authentication (MFA) for all TP-Link IDs.
- Rotate VPN Credentials: Promptly rotate any VPN credentials that may have been exposed due to these vulnerabilities.
- Limit Local Man-in-the-Middle Risks: Implement robust network access controls, including 802.1X, port security, Dynamic ARP Inspection, and wireless client isolation. Network segmentation can also help contain potential breaches.
- Continuous Monitoring: Maintain continuous intrusion detection and monitoring. Compromised provisioning systems can mimic legitimate network management activities, making vigilant oversight crucial for identifying anomalous behavior.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.