**Security researchers at Forescout have disclosed 15 new vulnerabilities in the zero-touch provisioning (ZTP) systems used by TP-Link’s Omada networking ecosystem, warning that some of the flaws can be chained to compromise entire fleets of managed devices. **
The vulnerabilities affect the ZTP protocols that allow routers, switches, and access points to be automatically configured by cloud-based, hardware, or software controllers, a process designed to reduce manual setup for network administrators managing multiple devices.
Forescout’s findings include the use of hardcoded cryptographic keys and certificates, insecure transmission of device and site credentials, weak certificate validation that enables man-in-the-middle attacks, a race condition in cloud-based device adoption, and a cross-site scripting flaw in controller web interfaces.
Researchers also identified issues such as predictable device serial numbers and default credentials that make it easier for attackers to enumerate and hijack devices.
Eleven of the 15 issues have been assigned CVE identifiers. TP-Link declined to assign CVEs to the remaining four, citing low severity.
By combining some of the newly discovered flaws with two previously disclosed vulnerabilities enabling remote code execution (CVE-2025-7850 and CVE-2025-7851), Forescout researchers demonstrated several practical attack paths.
In one scenario, an external attacker with no network access can exploit a race condition during cloud-based device adoption to intercept credentials and configuration data, ultimately gaining administrative control of a user’s cloud controller account and a foothold inside the internal network.
Other scenarios show that attackers positioned on a local network can impersonate controllers or devices to intercept credentials, decrypt protected traffic, or gain unauthorized access. However, in some cases an administrator must approve a spoofed device for the attack to work.
Because a single compromised controller can manage an entire fleet of devices, researchers noted that a successful attack chain could allow an intruder to gain a foothold inside the network and potentially achieve root-level command execution on the Omada devices it manages.
Omada controllers should not be exposed to the internet, but Forescout said it found 1,800 instances accessible from the web.
Beyond the Omada product line, researchers found that some of the same underlying weaknesses extend to other TP-Link products, including its VIGI IP camera platform, Festa routers, and the Tapo and Kasa smart home lines.
TP-Link has issued patches and advisories for a portion of the reported issues. The vendor indicated that remediation for some of the more structural weaknesses may not be complete until later in 2026, and some issues classified as ‘low severity’ will not be patched.
Forescout researchers will summarize the findings on Wednesday at the Black Hat cybersecurity conference in Las Vegas.
Related: Hackers Fail to Exploit Flaw in Discontinued TP-Link Routers
Related: TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking
Related: TP-Link Patches High-Severity Router Vulnerabilities