Researchers have uncovered critical flaws in TP-Link’s Omada platform that could allow attackers to impersonate devices, steal sensitive data, and gain unauthorised access, prompting the company to deploy security patches across its network infrastructure.
TP-Link has patched 15 vulnerabilities in its Omada business networking platform after researchers showed how flaws in its zero-touch provisioning system could let an attacker impersonate unregistered hardware, steal configuration data and, in some cases, intercept or alter network traffic. Forescout Research’s Vedere Labs presented the work at Black Hat USA 2026, describing weaknesses that affected selected controllers, gateways, switches, access points, optical line terminals and mobile apps tied to TP-Link’s cloud and provisioning infrastructure.
The core problem, according to Forescout, is the trust placed in the automated setup process that brings new devices online. In the scenarios it demonstrated, an attacker could exploit predictable device information, weak credential handling and insufficient certificate checks to pose as equipment waiting to be enrolled. That could expose controller logins, VPN material and other sensitive settings, while also opening a route into internal networks once the fake device was accepted.
Forescout said the new findings could also be chained with two earlier Omada flaws, CVE-2025-7850 and CVE-2025-7851, to obtain command execution and root access under certain conditions. The researchers also described a separate attack in which unsanitised registration data could be used to inject JavaScript into the controller interface and trick an administrator into surrendering cloud credentials. TP-Link said its disclosures were handled through coordinated vulnerability reporting and that fixes were rolled out in stages.
The reach of the issue appears wider than the enterprise controllers alone. Forescout said several TP-Link Android apps, including Omada, Tapo, Kasa, Tether, Deco and VIGI, shared weak certificate-validation behaviour and together had more than 70 million Google Play downloads, though that figure does not indicate compromise. The firm also estimated TP-Link may have 3 million to 7 million active cloud accounts and found more than 1,800 Omada controllers exposed online via Shodan, a reminder that internet-facing management systems remain an attractive target. Security advisers including INCIBE have urged users to install the latest firmware and rotate any credentials or VPN keys that may have been exposed.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





