Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical RCE in TP-Link Omada ER605 VPN Routers Exposes Hotel Guests
July 24, 2026
InfoStealer Logs Fuel Massive Cloud Data Breaches
July 24, 2026
Lampion RAT Malware Hidden in Fake Payment Receipt Emails
July 24, 2026
Home/Threats/Critical RCE in TP-Link Omada ER605 VPN Routers Exposes Hotel Guests
Threats

Critical RCE in TP-Link Omada ER605 VPN Routers Exposes Hotel Guests

Key Takeaways A critical vulnerability has been identified in TP-Link Omada ER605 VPN routers, enabling remote code execution (RCE). This flaw, tracked as CVE-2024-5035 with a CVSS score of 9.8,...

Sarah simpson
Sarah simpson
July 24, 2026 4 Min Read
2 0

Key Takeaways

  • A critical vulnerability has been identified in TP-Link Omada ER605 VPN routers, enabling remote code execution (RCE).
  • This flaw, tracked as CVE-2024-5035 with a CVSS score of 9.8, could allow attackers to hijack hotel Wi-Fi gateways.
  • Compromised gateways can silently redirect all guest traffic to malicious servers, facilitating credential harvesting and session hijacking.
  • The attack leverages DNS poisoning and, in some cases, Web Proxy Auto-Discovery (WPAD) abuse.
  • A patch is available, and immediate updates are crucial for affected organizations and hospitality providers.

TP-Link Omada ER605 VPN Routers Vulnerable to Critical RCE, Exposing Hotel Guests to DNS Poisoning

A severe remote code execution (RCE) vulnerability, identified as CVE-2024-5035, has been discovered in TP-Link Omada ER605 VPN routers. This flaw, boasting a critical CVSS score of 9.8, presents a significant risk, particularly for environments like hotels and conference centers that rely on these devices for guest Wi-Fi. A successful exploit could enable attackers to gain administrative control over the routers, subsequently redirecting all guest internet traffic to malicious infrastructure without their knowledge. This sophisticated attack vector bypasses traditional phishing and malware detection, posing a direct threat to corporate accounts and sensitive information.

Table Of Content

  • Key Takeaways
  • TP-Link Omada ER605 VPN Routers Vulnerable to Critical RCE, Exposing Hotel Guests to DNS Poisoning
  • The Attack Mechanism: DNS Poisoning and Impersonation
  • What You Should Do
  • Indicators of Compromise (IoCs):-

The core of this threat lies in the inherent trust users place in public Wi-Fi gateways. When travelers connect to hotel or conference networks, they assume the gateway will handle their internet requests securely. However, this vulnerability allows threat actors to exploit that trust by silently rerouting web requests through their controlled servers. This technique, described in detail in a report by Reliaquest, involves poisoning DNS responses at captive portal appliances to harvest Microsoft 365 credentials from employees on the go. This campaign has been observed in various cities across the United States, India, and Saudi Arabia, impacting guests from critical sectors such as finance, legal, healthcare, energy, and retail.

The Attack Mechanism: DNS Poisoning and Impersonation

According to Reliaquest’s Threat Research team, the tactics employed bear a resemblance to those used by APT28 (also known as Fancy Bear and Forest Blizzard), a group previously known for targeting SOHO routers by manipulating DNS settings. In this latest campaign, attackers alter DNS resolution at the gateway, causing users’ requests for legitimate domains to be silently resolved to attacker-controlled IP addresses. This redirection leads users to sophisticated, lookalike Microsoft login pages designed to capture credentials or exploit Microsoft’s device code flow.

The impact of such an attack is extensive and insidious. A single compromised captive portal appliance effectively becomes a man-in-the-middle for every device connecting to the network. This means that an employee simply opening a browser and encountering a seemingly legitimate Microsoft sign-in page could unknowingly expose their credentials. There is no need for a phishing email or a malicious download, making the attack highly effective and difficult for an average user to detect.

DNS poisoning attack flow (Source - Reliaquest)
DNS poisoning attack flow (Source – Reliaquest)

Reliaquest has identified several attacker-registered domains, including m365-owa.com, owa-ms365.com, ms365-device.com, and ms365-live.com, hosted on IP addresses 31.57.243.154 and 104.194.159.150. These domains are used to impersonate Microsoft services, enabling the theft of credentials or the abuse of Microsoft’s device code flow. This latter technique allows attackers to obtain OAuth tokens, granting them multi-factor authentication (MFA)-satisfied access to Microsoft 365 without directly compromising passwords, turning legitimate login prompts into silent session hijacks.

Furthermore, approximately one-third of the observed attacks involved the abuse of Web Proxy Auto-Discovery (WPAD). This allows Windows devices to fetch a malicious proxy auto-configuration file, silently routing additional traffic through attacker-controlled proxies. This method can make the malicious activity appear as normal HTTPS traffic in logs, making detection challenging for organizations without rigorous proxy authentication record reviews.

What You Should Do

  • Apply Patches Immediately: TP-Link has released firmware updates to address CVE-2024-5035. Organizations using Omada ER605 VPN routers must apply these patches without delay.
  • Implement Always-On VPN with Full Tunneling: Configure corporate VPNs to operate in an “always-on” full-tunnel mode. This ensures all DNS requests are routed through trusted corporate resolvers, bypassing potentially compromised public Wi-Fi gateways. Audit for split tunneling exceptions that could allow DNS or authentication traffic to bypass the VPN.
  • Enforce Strict Encrypted DNS: Configure endpoint DNS encryption tools to operate in strict mode (e.g., DNS over HTTPS or DNS over TLS). Avoid opportunistic modes that allow plaintext fallback, as this creates a vulnerability for DNS poisoning.
  • Disable WPAD Where Unnecessary: If Web Proxy Auto-Discovery (WPAD) is not essential for your organization, disable it. If it must remain enabled, restrict proxy auto-configuration file retrieval to approved internal hosts only.
  • Educate Employees on URL and Certificate Verification: Train employees to meticulously verify URLs and SSL/TLS certificates before entering any credentials, especially when connecting to public Wi-Fi networks in hotels, airports, or conference centers.
  • Restrict Microsoft Device Code Authentication Flow: Utilize Conditional Access policies in Microsoft Entra ID to block the device code authentication flow for most users. This flow has limited legitimate uses for typical users and, if abused, can provide attackers with MFA-satisfied access.
  • Monitor for Indicators of Compromise (IoCs): Implement continuous monitoring for the following IoCs in your network logs:

Indicators of Compromise (IoCs):-

Type Indicator Description
IP address 38.146.28.75 DNS poisoning response IP address observed in forged DNS replies.
IP address 31.57.243.154 DNS poisoning response IP hosting ms365-device.com, owa-ms365.com, and m365-owa.com.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

InfoStealer Logs Fuel Massive Cloud Data Breaches

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft detects 7.6B email phishing threats, Teams vishing up 10x
July 24, 2026
Russian Hackers Exploit Critical Zimbra Zero-Day to Steal Emails
July 24, 2026
Decathlon Investigates Alleged Breach of 160 Million Customer Records
July 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us