Forescout Finds 15 TP-Link Omada Flaws in Zero-Touch Provisioning
Security researchers warn that automated onboarding flaws could allow attackers to hijack devices and infiltrate internal networks.
Security researchers from Forescout's Vedere Labs have disclosed 15 vulnerabilities within TP-Link's Omada software-defined networking (SDN) ecosystem. The flaws primarily target the Zero-Touch Provisioning (ZTP) process, potentially allowing attackers to hijack devices, spoof identities, and infiltrate internal networks.
Presented at Black Hat USA 2026, the research categorizes the 15 bugs into four primary areas: device hijacking and spoofing, client-side code execution, sensitive information disclosure, and compromises to encryption and the chain of trust. Among the most critical findings are hard-coded private keys in Omada protocol versions 1 and 2 (CVE-2025-15627 and CVE-2025-15628), as well as a cloud device-adoption race condition identified as CVE-2025-15630. According to the researchers, attackers can leverage predictable, sequential serial numbers to impersonate devices and use default 'admin/admin' credentials to extract cleartext configuration data.
The Risk of Automated Trust
Zero-Touch Provisioning is an industry-standard method designed to automatically configure new network devices via a central server, removing the need for manual setup. While this efficiency is vital for large-scale deployments, Forescout argues it often creates a "blind trust" scenario. Francesco La Spina, a Forescout researcher, noted that while ZTP does not inherently expand the attack surface, it can increase it in practice by collapsing multiple independent trust decisions into a single automated flow.
Systemic Industry Implications
Because TP-Link holds a significant global market share in WLAN technology—estimated between 15% and 45%—these vulnerabilities represent a systemic risk. The impact is not limited to the Omada ecosystem; the research indicates that the flaws extend to VIGI surveillance platforms, Festa products, and mobile applications including Tapo, Kasa, and Tether. This highlights a broader tension between the convenience of automation and the security requirements of Zero Trust architectures.
Moving Toward Zero-Trust Provisioning
Forescout researchers suggest that the industry must move away from assuming automation is inherently secure. Stanislav Dashevskyi of Forescout remarked that the most common mistake organizations make is trusting that the technology would simply "work" without underlying vulnerabilities, suggesting that ZTP should instead be treated as "Zero-Trust Provisioning."
Moving forward, the industry must prioritize rigorous segmentation and secret hygiene to prevent automated onboarding from becoming a high-blast-radius target. Organizations using TP-Link's SDN ecosystem should monitor for official patches and review their device authentication protocols to mitigate the risk of device impersonation.