15 Flaws in TP-Link Kit Put Automatic Network Setup at Risk
Security researchers found 15 vulnerabilities in TP-Link's Omada networking system and warn that the convenient zero-touch setup process millions of organisations rely on could hand criminals the keys to an entire network.

Key points
- Forescout's Vedere Labs disclosed 15 vulnerabilities in TP-Link's Omada networking platform at Black Hat USA 2026 in Las Vegas.
- TP-Link products are used by an estimated 1.7 billion people across more than 170 countries.
- The flaws can be chained together to let an outside attacker impersonate a trusted device and take control of an organisation's entire network.
- Patches required more than a year of back-and-forth between Forescout and TP-Link because some bugs were baked into core design choices.
- Researchers say zero-touch provisioning is still a net positive, but only when organisations treat it with the same scepticism they apply to anything connected to the internet.
TP-Link is everywhere. Its hardware sits inside schools, hospitals, and corporate offices across more than 170 countries, and by the company's own count, 1.7 billion people use its products. That ubiquity is now a problem.
At Black Hat USA in Las Vegas this week, Vedere Labs researchers Stanislav Dashevskyi and Francesco La Spina revealed 15 security flaws in TP-Link Omada, the software system that ties the company's networking hardware together and lets organisations manage it from one place. We first covered the Omada vulnerability research on 4 August, when Forescout's findings were still under embargo.
How did the attack work?
The core issue isn't the devices themselves. It's the way organisations set them up using zero-touch provisioning, or ZTP: a process that lets a business automatically configure every new router or switch it buys without manually touching each one. Convenient, yes. But convenience has a price.
Because TP-Link assigns device serial numbers in a predictable sequence, a criminal who knows one serial number can guess the next. Dashevskyi and La Spina showed how an attacker could exploit that fact to impersonate a new device before it connects to the company's network, then authenticate using TP-Link's factory-default username and password, both of which are simply "admin".
Once inside, the attacker receives configuration files in plain, readable text containing passwords and other secrets. From there they could phish a network administrator, tricking that person into handing over their own login. With those credentials, one criminal could control every device on the network.
The researchers also mapped four attack routes for criminals already inside a network, including remote code execution (running their own software on a target machine with the highest possible privileges) and man-in-the-middle attacks, where the criminal quietly reads or alters data passing between two parties who believe they're communicating privately.
TP-Link's smart home gadgets and surveillance cameras share parts of the same underlying system, so video management software turned out to be vulnerable in similar ways, potentially letting attackers intercept footage from security cameras.
Why did fixing this take so long?
Some of the flaws weren't simple coding errors. They were built into fundamental design decisions inside the Omada protocols, meaning TP-Link couldn't patch them with a quick software update. Forescout first reported the issues well over a year before all fixes were confirmed, a timeline that's long even by industry standards.
The 15 flaws span four categories:
| Category | What it allows |
|---|---|
| Device hijacking and spoofing | Impersonating trusted hardware on the network |
| Client-side code execution | Running attacker-chosen software on connected machines |
| Sensitive information disclosure | Stealing passwords and configuration secrets |
| Encryption and trust-chain failures | Undermining the checks that verify a device is legitimate |
Most are rated medium or high severity under CVSS, the Common Vulnerability Scoring System the security industry uses to rank how dangerous a flaw is.
Should network admins be worried right now?
Patches are now available. Anyone running TP-Link Omada hardware should check the TP-Link security advisory page for the latest firmware and apply it immediately.
Beyond patching, La Spina's framing deserves attention: the provisioning server, the machine that automatically configures everything else, is a single high-value target. If it falls, everything it has ever configured is at risk. Organisations should isolate that server, change all default credentials before deployment, and never assume a device is trustworthy simply because the setup process said it connected successfully.
For most home users the risk is low, provided your ISP keeps your firmware current. If you manage a TP-Link business network yourself, treat this as a prompt to audit your Omada installation today.
The deeper point here is what Dashevskyi calls the real danger: not any single bug, but the variety of them, giving attackers the flexibility to adapt attacks across local, internet-facing, and social-engineering scenarios. ZTP's growth, projected at 100 to 200 percent over the next decade according to industry forecasts cited by Forescout, means this attack surface is only expanding. Vedere Labs has put the provisioning layer on the map as a target class. Expect others to follow.



