TP-Link patches Omada ZTP flaws enabling network breaches
🔒 TP-Link patched 15 vulnerabilities in the Omada zero-touch provisioning (ZTP) mechanism that could be chained with earlier flaws to achieve remote code execution and full network compromise. Forescout’s Vedere Labs disclosed the issues at Black Hat USA, noting impacts across Omada controllers, gateways, switches, access points, cloud services, mobile apps, and various TP-Link devices. The flaws include hard-coded keys, information disclosure, device hijacking, client-side code execution, and interception of encrypted communications. Administrators are urged to apply firmware updates, use strong unique credentials, enable MFA, rotate secrets if compromise is suspected, and monitor for suspicious activity.
