15 Flaws in TP-Link Kit Put Automatic Network Setup at Risk

Security researchers found 15 vulnerabilities in TP-Link's Omada networking system and warn that the convenient "zero-touch" setup process that millions of organisations rely on could hand criminals the keys to an entire network.

ThreatVectr Newsdesk· 4 min read
Full-frame photoreal editorial image of a modern enterprise data centre corridor at night, glowing amber server indicator lights reflecting off a polished floor
Share

Key points

  • Forescout's Vedere Labs disclosed 15 vulnerabilities in TP-Link's Omada networking platform at Black Hat USA 2026 in Las Vegas.
  • TP-Link products are used by an estimated 1.7 billion people across more than 170 countries.
  • The flaws can be chained together to let an outside attacker impersonate a trusted device and take control of an organisation's entire network.
  • Patches required more than a year of back-and-forth between Forescout and TP-Link because some bugs were baked into core design choices.
  • Researchers say zero-touch provisioning is still a net positive, but only when organisations treat it with the same scepticism they apply to anything connected to the internet.

TP-Link is everywhere. The company's routers, switches, and Wi-Fi access points sit inside homes, schools, hospitals, and corporate offices across more than 170 countries. By the company's own count, 1.7 billion people use its products. That ubiquity is now a problem.

At the Black Hat USA security conference in Las Vegas this week, researchers Stanislav Dashevskyi and Francesco La Spina from Forescout's Vedere Labs unit revealed 15 security flaws in TP-Link Omada, which is the software system that ties the company's networking hardware together and lets organisations manage it all from one place.

How did the attack work?

The core issue is not the devices themselves. It is the way organisations set them up using a process called zero-touch provisioning, or ZTP. ZTP lets a business automatically configure every new router or switch it buys without anyone manually touching each one. Convenient, yes. But convenience has a price.

Because TP-Link assigns device serial numbers in a predictable sequence, a criminal who knows one serial number can guess the next. Dashevskyi and La Spina showed how an attacker could use that fact to impersonate a new device before it connects to the company's network, then log in using TP-Link's factory-default username and password, both of which are simply "admin".

Once inside, the attacker receives configuration files in plain, readable text containing passwords and other secrets. From there they could send a fake email or message to a network administrator, a technique known as phishing, tricking that person into handing over their own login. With those credentials, one criminal could control every device on the network.

The researchers also mapped out four attack routes for criminals who are already inside a network, including remote code execution, which means running their own software on a target machine with the highest possible privileges, and man-in-the-middle attacks, where the criminal quietly reads or alters data passing between two parties who believe they are communicating privately.

TP-Link's smart home gadgets and surveillance cameras share parts of the same underlying system, so video management software turned out to be vulnerable in similar ways, potentially letting attackers intercept footage from security cameras.

Why did fixing this take so long?

Some of the flaws were not simple coding errors. They were built into fundamental design decisions inside the Omada protocols, meaning TP-Link could not patch them with a quick software update. Forescout first reported the issues to TP-Link well over a year before all fixes were confirmed, a timeline that is long even by industry standards.

The 15 flaws span four categories:

Category What it allows
Device hijacking and spoofing Impersonating trusted hardware on the network
Client-side code execution Running attacker-chosen software on connected machines
Sensitive information disclosure Stealing passwords and configuration secrets
Encryption and trust-chain failures Undermining the checks that verify a device is legitimate

Most are rated medium or high severity under CVSS, the Common Vulnerability Scoring System that the security industry uses to rank how dangerous a flaw is.

Should network admins be worried right now?

Patches are now available, so the first step is updating. Anyone running TP-Link Omada hardware should check the TP-Link security advisory page for the latest firmware versions and apply them immediately.

Beyond patching, Forescout's broader point is worth sitting with. La Spina put it plainly: the central provisioning server, the machine that automatically configures everything else, is a single high-value target. If it falls, everything it has ever configured is at risk. Organisations should isolate that server, change all default passwords before deployment, and never assume a device is trustworthy simply because the setup process said it connected successfully.

For most ordinary users, the risk is low provided your internet service provider keeps your home router firmware up to date. If you manage a TP-Link business network yourself, treat this as a prompt to audit your Omada installation today.

© 2026 Threat Vectr