Fifteen Flaws in TP-Link's Auto-Setup System Could Hand Hackers Control of an Entire Business Network
Forescout found serious weaknesses in the technology TP-Link uses to automatically configure routers, switches, and cameras. Chain enough of them together and an outsider can quietly seize every device on the network.

Key points
- Forescout disclosed 15 vulnerabilities in TP-Link Omada's zero-touch provisioning system on 6 August 2025, eleven of which carry CVE identifiers.
- Chaining several flaws with two remote code execution bugs (CVE-2025-7850 and CVE-2025-7851) can give an outsider administrative control of a cloud account and root-level access to every managed device.
- Forescout found 1,800 Omada controllers exposed directly to the public internet, despite TP-Link's own guidance that they should never be.
- Affected products extend beyond Omada to TP-Link's VIGI cameras and the Tapo and Kasa smart-home lines.
- TP-Link has issued partial patches; some structural fixes aren't expected before late 2026, and four issues the company rated low-severity won't be patched at all.
TP-Link's Omada system is popular in small offices and hospitality businesses because it lets one person manage dozens of routers, switches, and wireless access points from a single dashboard. The centrepiece is zero-touch provisioning, or ZTP, which automatically sets up devices the moment they're plugged in.
Forescout spent several months pulling that process apart. The results are not pretty.
How bad is this, really?
Bad enough that a complete outsider could potentially end up with administrative access to an entire business network. Working examples were demonstrated.
The weaknesses include hardcoded cryptographic keys (secret codes baked permanently into the software that can't be changed), insecure transmission of credentials, and weak checks that let a criminal insert themselves silently between two devices. That last technique is called a man-in-the-middle attack. Forescout also found predictable device serial numbers and default credentials that make hijacking individual devices easier.
One particularly worrying path exploits a race condition during cloud-based device setup. A race condition is a timing flaw where two processes run in an unexpected order, letting an attacker slip in and steal credentials before legitimate setup completes. From there, a criminal can take over the cloud controller account and reach inside the internal network.
| Vulnerability | CVE ID | What it allows |
|---|---|---|
| Remote code execution (RCE) | CVE-2025-7850 | Run attacker commands on the device |
| Remote code execution (RCE) | CVE-2025-7851 | Run attacker commands on the device |
| Race condition in cloud adoption | Assigned | Steal credentials during auto-setup |
| Hardcoded cryptographic keys | Assigned | Decrypt protected traffic |
| Weak certificate validation | Assigned | Man-in-the-middle interception |
Because a single Omada controller manages every device on the network, one successful takeover cascades. Everything the controller touches is at risk. We first tracked CVE-2025-7850 and CVE-2025-7851 on 4 August 2026; seeing them now anchoring a full network-takeover chain is a meaningful escalation.
Who is affected?
Anyone running TP-Link Omada hardware should check for updates now. The same underlying weaknesses exist in TP-Link's VIGI IP security cameras and the Tapo and Kasa smart-home lines, which are common in ordinary households.
Forescout researchers will present the full findings at Black Hat in Las Vegas this week. TP-Link has released patches for some issues, but fixes for deeper structural problems may not arrive until late 2026. Four low-severity issues won't be patched at all.
Should you worry?
If you manage an Omada controller, confirm it isn't reachable from the public internet. Forescout found 1,800 that were. That's the single highest-priority fix, and it costs nothing.
The detail worth watching isn't the RCE bugs, which are serious on their own. It's the structural problems scheduled for late 2026 at earliest: a year of known, unfixed weaknesses in kit that sits at the centre of networks it's meant to protect.



