Security researchers at Forescout have uncovered 15 significant vulnerabilities within the zero-touch provisioning systems of TP-Link's Omada networking ecosystem. These vulnerabilities pose a substantial risk as they can be exploited in combination to compromise entire networks managed by the Omada system. The vulnerabilities affect the protocols used for automatic configuration of routers, switches, and access points, which are designed to ease the management burden on network administrators.

Key issues identified include the use of hardcoded cryptographic keys, insecure transmission of credentials, and weak certificate validation that allows for man-in-the-middle attacks. Additional flaws include race conditions in cloud-based device adoption and cross-site scripting vulnerabilities in controller web interfaces. Some devices are at risk due to predictable serial numbers and default credentials, making them easier targets for attackers.

While 11 of the vulnerabilities have been assigned CVE identifiers, TP-Link decided not to assign CVEs to four others, citing their lower severity. By leveraging these new vulnerabilities alongside previously disclosed ones, attackers can execute remote code, gaining administrative control and potentially achieving root-level command execution on Omada devices.

Forescout warns that Omada controllers should not be exposed to the internet, yet found 1,800 instances accessible online. Some vulnerabilities extend beyond Omada, affecting other TP-Link products like VIGI IP cameras and Tapo smart home devices. TP-Link has released patches for some issues, but structural weaknesses may not be fully addressed until 2026. The researchers will present their findings at the upcoming Black Hat conference.