TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices
Omada platform was found to be vulnerable in several ways
by https://www.techradar.com/uk/author/sead-fadilpai · TechRadarNews By Sead Fadilpašić Published 5 August 2026
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter
- Forescout’s Vedere Labs found 15 flaws in TP‑Link Omada business networking gear, exploitable for RCE when chained with prior CVEs
- Weak trust shortcuts in zero‑touch provisioning exposed devices to client‑side code execution, hijacking, spoofing, and encrypted comms compromise
- TP‑Link released firmware updates; admins should patch immediately, with 1,800+ Omada controllers exposed online
TP-Link has patched more than a dozen vulnerabilities across multiple business networking products which could have been chained to achieve remote code execution (RCE).
Security researchers at Vedere Labs from Forescout found the flaws and published an in-depth report on the issues, which particularly affect TP-Link Omada, the company’s business networking platform for centrally managing enterprise and small-business network infrastructure.
It includes cloud-managed Wi-Fi access points, routers, switches, gateways, and controllers, all of which can be monitored and configured from a single interface.
Latest Videos FromTechRadarWatch full video here:
Enabling "concrete attacks"
These support zero-touch provisioning (ZTP), a mechanism that allows IT managers to deploy and maintain devices without needing to configure each one manually and on site.
However, ZTP has to establish trust between a factory-fresh device, and a controller with no human involved, so TP-Link used different shortcuts: from hard-coded keys and certificates shared across multiple devices, to default credentials, and from guessable serial numbers as “identity”, to weak session-key randomness.
Now, Forescout says 15 vulnerabilities its researchers discovered all allow for different ways of exploiting these shortcuts, meaning a flaw anywhere in the onboarding chain can compromise every device that goes through it. These bugs would need to be combined with two previously disclosed command-injection flaws, though.
“The vulnerabilities fall into four impact categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications,” Forescout said. “Combined with two previously disclosed CVEs (CVE-2025-7850 and CVE-2025-7851), these flaws enable concrete attacks that let attackers infiltrate networks through controllers and client devices.”
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors