TP-Link has patched 15 vulnerabilities in the zero touch provisioning system behind its Omada networking line after Forescout’s Vedere Labs researchers showed the flaws could be chained together to move from adopting a single new device to compromising an entire network.
Per TP-Link’s advisory, the issues, presented by Forescout at Black Hat USA 2026 and DEF CON, span hardcoded cryptographic keys, insecure transmission of device and site credentials, weak certificate validation that enables man in the middle interception, a race condition in cloud based device adoption, and cross site scripting in controller web interfaces. Eleven of the fifteen received CVE identifiers, including CVE-2025-9291, CVE-2025-15544, and CVE-2025-15627 through CVE-2025-15631; TP-Link says the other four were rated low severity and did not receive CVEs. The advisory covers Omada controllers, gateways, switches, access points, OLT platforms, cloud services, and the TP-Link mobile apps used to manage them.
Zero touch provisioning exists to let a controller automatically authenticate and configure new hardware with no manual setup, a convenience feature aimed squarely at small and midsize IT teams managing many sites. Forescout’s research found roughly 1,800 Omada controllers reachable directly from the public internet despite TP-Link’s own guidance against exposing them, and per the advisory the vulnerabilities are exploited by chaining several together rather than through any single flaw, meaning isolated patching of one CVE will not fully close the path from device adoption to network takeover.
The disclosure is a useful companion to CyberTech’s coverage of the hardcoded credential exposed in Cisco’s Firewall Management Center: automated provisioning and trust establishment systems are increasingly where the credential handling mistakes live, not in the day to day managed device itself. Security teams running Omada or similar zero touch fleets should confirm the provisioning channel itself is patched and not internet facing, rather than treating the adopted end devices as the only thing worth auditing.