Fifteen Flaws in TP-Link's Auto-Setup System Could Hand Hackers Control of an Entire Business Network
Security firm Forescout found serious weaknesses in the technology TP-Link uses to automatically configure routers, switches, and cameras. Some flaws can be chained together to let an outsider quietly seize control of every device on a network.

Key points
- Forescout disclosed 15 vulnerabilities in TP-Link Omada's zero-touch provisioning system on 6 August 2025, eleven of which carry official CVE identifiers.
- Chaining several flaws with two remote code execution bugs (CVE-2025-7850 and CVE-2025-7851) can give an outsider administrative control of a cloud account and root-level access to every managed device.
- Forescout found 1,800 Omada controllers exposed directly to the public internet, despite TP-Link's own guidance that they should never be.
- Affected products extend beyond Omada to TP-Link's VIGI cameras, Festa routers, and Tapo and Kasa smart-home lines.
- TP-Link has issued partial patches; some structural fixes are not expected before late 2026, and four issues the company rated low-severity will not be patched at all.
TP-Link's Omada system is popular in small offices, schools, and hospitality businesses because it lets one person manage dozens of routers, switches, and wireless access points from a single dashboard. The centrepiece is a feature called zero-touch provisioning, or ZTP, which automatically sets up and configures devices the moment they are plugged in, with no manual steps required.
Forescout, a network security research firm, spent several months pulling that auto-setup process apart. What they found is not pretty.
How bad is this, really?
Bad enough that a complete outsider, sitting anywhere on the internet, could potentially end up with administrative access to a business's entire network. The attack requires chaining several of the new flaws together, but Forescout demonstrated working examples.
The weaknesses include hardcoded cryptographic keys (secret codes baked permanently into the software that cannot be changed), insecure transmission of passwords and site credentials, and weak checks that allow a criminal to insert themselves silently between two devices and read traffic that should be private. This type of interception is called a man-in-the-middle attack.
One particularly worrying path exploits a race condition during cloud-based device setup. A race condition is a timing flaw where two processes run in an unexpected order, letting an attacker slip in and steal credentials before the legitimate setup completes. From there, a criminal can take over the cloud controller account and gain a foothold inside the internal network.
| Vulnerability | CVE ID | What it allows |
|---|---|---|
| Remote code execution (RCE) | CVE-2025-7850 | Run attacker commands on the device |
| Remote code execution (RCE) | CVE-2025-7851 | Run attacker commands on the device |
| Race condition in cloud adoption | Assigned | Steal credentials during auto-setup |
| Hardcoded cryptographic keys | Assigned | Decrypt protected traffic |
| Weak certificate validation | Assigned | Man-in-the-middle interception |
Because a single Omada controller manages every device on the network, one successful takeover cascades. Everything the controller touches is at risk.
Who is affected?
Anyone running TP-Link Omada hardware at home or at work should check for updates now. The problems extend beyond Omada: Forescout confirmed the same underlying weaknesses exist in TP-Link's VIGI IP security cameras, Festa routers, and the Tapo and Kasa smart-home product lines, which are common in ordinary households.
Forescout researchers will present the full findings at the Black Hat security conference in Las Vegas this week. TP-Link has released patches for some of the issues, but the company told Forescout that fixes for the deeper structural problems may not arrive until late 2026. Four issues rated low-severity by TP-Link will receive no patch at all.
If you manage an Omada controller, make sure it is not reachable from the public internet. Forescout found 1,800 that were. That is the single highest-priority fix, and it costs nothing.



