Security firm Forescout has disclosed 15 new vulnerabilities in the zero-touch provisioning systems used across TP-Link’s Omada networking ecosystem, some of which chain together into the compromise of entire fleets of managed devices. The findings are being presented at Black Hat, and 11 of the issues have CVE identifiers, with TP-Link declining to assign CVEs to the remaining four after citing low severity.
The Zero-Touch Provisioning Flaws Forescout Found in the Omada Ecosystem
Zero-touch provisioning is the mechanism TP-Link uses to adopt and configure network devices automatically, and weaknesses in that process are especially dangerous because they sit at the point where devices are first onboarded. Forescout’s findings include hardcoded cryptographic keys and certificates, insecure transmission of device and site credentials, weak certificate validation enabling man-in-the-middle attacks, a race condition in cloud-based device adoption, and a cross-site scripting flaw in controller web interfaces, alongside predictable device serial numbers and default credentials.
Hardcoded Keys, Weak Validation, and the Cloud Adoption Race Condition
The issues span several layers of the provisioning flow. Hardcoded cryptographic material and insecure credential handling can let an attacker intercept or forge device identities, while weak certificate validation opens a man-in-the-middle path. The race condition in cloud-based device adoption, combined with predictable serial numbers and default credentials, gives an attacker a foothold they can use before a device is fully and securely registered.
Chaining the Flaws With Earlier TP-Link RCEs for Full Network Control
Forescout found that the new issues can be chained with two previously disclosed remote code execution vulnerabilities, CVE-2025-7850 and CVE-2025-7851, to unlock several practical attack paths. An external attacker with no network access can exploit the race condition to intercept credentials and configuration and gain administrative control of the cloud controller account, establishing a foothold inside the internal network. Local attackers can impersonate controllers or devices to intercept credentials or decrypt protected traffic.
A Single Compromised Controller Can Govern an Entire Fleet
Because a single Omada controller can manage an entire fleet of routers, switches, and access points, compromising the controller can yield root-level command execution on all the managed devices under it. That fleet-wide consequence is what elevates these flaws from individual-device issues to a network-takeover scenario, and why their chaining matters more than any single vulnerability on its own.
Internet-Exposed Controllers and the Scope of Affected Products
Forescout reported finding roughly 1,800 internet-exposed Omada controller instances, giving external attackers a wide target population. The same underlying weaknesses extend beyond the Omada ecosystem to TP-Link’s VIGI cameras, Festa routers, and Tapo and Kasa smart-home product lines, broadening the potential impact to consumer and small-business environments as well as enterprise LANs.
Partial Patches and Fixes Deferred to Later in the Year
TP-Link has issued patches for a portion of the issues, according to Forescout, while some structural fixes may not complete until later in 2026 and a few low-severity issues will not be patched at all. The company’s decision to decline CVE identifiers for the four low-severity findings means those issues will not carry the same public visibility in vulnerability databases.
What the Omada Findings Mean for Network and Fleet Management
The presence of 1,800 internet-exposed controllers combined with fleet-wide adoption logic creates a real network-takeover risk for SMB and enterprise LANs, and the recommendation that organizations avoid exposing Omada controllers to the internet is central to reducing exposure while patches are incomplete. For products that rely on zero-touch provisioning, the episode shows that the convenience of automated onboarding carries a security cost that must be weighed when designing device adoption.
The range of weaknesses Forescout catalogued — from hardcoded cryptography to insecure credential transmission to default credentials — points to foundational hardening gaps across the provisioning stack rather than a single defect. The fact that some structural fixes will stretch into later in the year means administrators must rely on compensating controls in the interim.
For defenders, the practical guidance is straightforward: keep controllers off the public internet, apply the patches TP-Link has released, and treat the provisioning process as a component of the attack surface that needs the same monitoring as the network itself. A single compromised controller taking over an entire fleet makes the security of the management plane as important as the security of every device it governs.
