Full Report
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]
Analysis Summary
# Vulnerability: TP-Link Omada Zero-Touch Provisioning (ZTP) Vulnerability Chain
## CVE Details
- **CVE IDs:**
- CVE-2025-9289 through CVE-2025-9293
- CVE-2025-15544
- CVE-2025-15627 through CVE-2025-15631
- Previously disclosed: CVE-2025-7850, CVE-2025-7851 (Command Injection)
- **CVSS Score:** Not explicitly listed in the article (Severity: High/Critical when chained)
- **CWE:** Hard-coded cryptographic keys, Information Disclosure, Command Injection, Race Condition, Weak Authentication.
## Affected Systems
- **Products:** Omada Controllers (Software/Hardware), Gateways, Switches, Access Points, OLT platforms, TP-Link Cloud services, and Mobile Applications (Omada, Omada Guard).
- **Versions:** Various versions prior to August 2026 patches.
- **Configurations:** Systems utilizing Zero-Touch Provisioning (ZTP) and devices exposed directly to the internet (estimated 1,800+ controllers).
## Vulnerability Description
The vulnerabilities exist in the Zero-Touch Provisioning (ZTP) mechanism and the Omada management ecosystem. Key technical flaws include:
1. **Predictable Identifiers:** Serial numbers are predictable, allowing attackers to enumerate devices and obtain MAC addresses.
2. **Race Conditions:** Flaws in the cloud adoption process allow attackers to impersonate devices during the provisioning phase.
3. **Credential Issues:** Use of default credentials during initial adoption and storage of unsalted MD5 password hashes.
4. **Information Disclosure:** Unauthenticated temporary download links and insecure disclosure of device configurations (including VPN keys).
5. **Chain of Trust Compromise:** These flaws can be chained with existing command-injection vulnerabilities to achieve Remote Code Execution (RCE) on network infrastructure.
## Exploitation
- **Status:** PoC disclosed at Black Hat USA; no confirmed reports of exploitation in the wild at the time of the report.
- **Complexity:** Medium (Requires chaining multiple flaws and timing race conditions).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Disclosure of cleartext usernames, password hashes, and VPN keys).
- **Integrity:** High (Ability to reconfigure managed devices and inject malicious JavaScript).
- **Availability:** High (Potential for full device takeover and network disruption via RCE).
## Remediation
### Patches
- Users should update to the latest firmware and software versions via the TP-Link Omada Download Portal: hxxps[://]support[.]omadanetworks[.]com/en/download/
- Update mobile applications (Omada and Omada Guard) via official app stores.
### Workarounds
- **Credential Management:** Change all default credentials to strong, unique passwords.
- **MFA:** Enable Multi-Factor Authentication for cloud-managed accounts.
- **Access Control:** Avoid exposing Omada controllers directly to the public internet; use VPNs for management access.
- **Secret Rotation:** Rotate all administrative secrets and VPN keys if a compromise is suspected.
## Detection
- **Indicators of Compromise:** Unusual administrative logins, unauthorized configuration changes, or suspicious JavaScript execution in the management console.
- **Detection Methods:** Monitor network traffic for unauthorized communication with unknown controllers and audit logs for failed adoption attempts or rapid enumeration of serial numbers.
## References
- TP-Link Advisory: hxxps[://]support[.]omadanetworks[.]com/us/document/130627/
- Forescout Research: hxxps[://]www[.]forescout[.]com/blog/new-tp-link-router-vulnerabilities-exploiting-zero-touch-provisioning/
- Original News Source: hxxps[://]www[.]bleepingcomputer[.]com/news/security/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks/