• News/
  • bleepingcomputer-20260804221820

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

BleepingComputer
·
Bill Toulas
·
Published Aug 4, 2026
·
Updated

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). The flaws were uncovered by Forescout’s Vedere Labs researchers, who published the full details at the Black Hat USA security conference earlier today. Omada is TP-Link’s business networking product line that includes Wi-Fi access points, Ethernet and PoE switches, internet gateways, and VPN routers. They are typically used by small to medium-sized businesses, although TP-Link also markets pro-grade deployments for enterprises. ZTP is a way to deploy network devices without manually configuring each one on-site, allowing an IT team or managed service provider (MSP) to prepare everything remotely based on a predetermined configuration. Some of the 15 flaws Forescout discovered also impact various TP-Link products and services, such as IP cameras, smart home IoT devices, mobile applications, and cloud accounts. The issues include hard-coded cryptographic keys, information disclosure, remote code execution, device hijacking and spoofing, client-side code execution, and interception or compromise of encrypted communications. Forescout says attackers could combine the new flaws with two previously disclosed command-injection vulnerabilities to compromise Omada’s chain of trust and infiltrate networks. “The vulnerabilities fall into four impact categories: client-side code ex...

Read full article

Affected Software

9 affected components
TP-Link Omada network devices (zero-touch provisioning / ZTP mechanism)
TP-Link Omada Controllers
TP-Link Omada Gateways
TP-Link Omada Switches
TP-Link Omada Access Points
TP-Link Omada OLT platforms
TP-Link Omada Cloud services
TP-Link Omada mobile applications
TP-Link Omada Guard mobile application
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities did TP-Link patch in their Omada devices?

TP-Link patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices.

2

What security risks are associated with these vulnerabilities?

The vulnerabilities could be chained with previously disclosed flaws to achieve remote code execution (RCE).

3

Who discovered the vulnerabilities in TP-Link Omada devices?

The vulnerabilities were uncovered by researchers from Forescout’s Vedere Labs.

4

Which TP-Link products are affected by these patched vulnerabilities?

Affected products include TP-Link Omada Controllers, Gateways, Switches, Access Points, OLT platforms, and mobile applications.

5

When were the vulnerabilities in TP-Link Omada devices publicly disclosed?

The vulnerabilities were publicly disclosed on August 4, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203