TP-Link has addressed 15 vulnerabilities within the zero-touch provisioning (ZTP) mechanism of its Omada network devices. These security flaws were identified by Forescout’s Vedere Labs researchers and publicly detailed at the Black Hat USA security conference.
Omada is TP-Link's product line for business networking, encompassing Wi-Fi access points, Ethernet switches, internet gateways, and VPN routers. These devices are commonly deployed in small to medium-sized businesses and enterprise environments.
The discovered vulnerabilities, when combined with two previously disclosed command-injection flaws (CVE-2025-7850 and CVE-2025-7851), could allow attackers to achieve remote code execution (RCE). This chain of exploits could compromise Omada’s chain of trust and enable infiltration of networks.
The issues include hard-coded cryptographic keys, information disclosure, device hijacking and spoofing, client-side code execution, and the interception or compromise of encrypted communications. Some of these vulnerabilities also extend to other TP-Link products, such as IP cameras, smart home IoT devices, mobile applications, and cloud accounts.
TP-Link's advisory lists 11 of the 15 newly disclosed flaws with CVE identifiers, including CVE-2025-9289 through CVE-2025-9293, CVE-2025-15544, and CVE-2025-15627 through CVE-2025-15631.
The remaining four findings, which did not receive CVE tracking numbers, involve device adoption based solely on serial numbers, default credentials used during initial adoption, predictable serial numbers, and files accessible via unauthenticated temporary download links. Forescout described a scenario where a remote attacker could enumerate predictable device serial numbers to identify devices awaiting adoption.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
TP-Link has released patches for 15 vulnerabilities found in the zero-touch provisioning (ZTP) mechanism of its Omada network devices. These flaws, when chained with previously disclosed command-injection vulnerabilities, could enable remote code execution and allow attackers to infiltrate networks. The vulnerabilities affect TP-Link's business networking product line, Omada, which is used by small to medium-sized businesses and enterprises.