TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices

Security News

TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices

Credit: The original article is published here.
  • Forescout’s Vedere Labs found 15 flaws in TP‑Link Omada business networking gear, exploitable for RCE when chained with prior CVEs
  • Weak trust shortcuts in zero‑touch provisioning exposed devices to client‑side code execution, hijacking, spoofing, and encrypted comms compromise
  • TP‑Link released firmware updates; admins should patch immediately, with 1,800+ Omada controllers exposed online

TP-Link has patched more than a dozen vulnerabilities across multiple business networking products which could have been chained to achieve remote code execution (RCE).

Security researchers at Vedere Labs from Forescout found the flaws and published an in-depth report on the issues, which particularly affect TP-Link Omada, the company’s business networking platform for centrally managing enterprise and small-business network infrastructure.

It includes cloud-managed Wi-Fi access points, routers, switches, gateways, and controllers, all of which can be monitored and configured from a single interface.

Enabling “concrete attacks”

These support zero-touch provisioning (ZTP), a mechanism that allows IT managers to deploy and maintain devices without needing to configure each one manually and on site.

However, ZTP has to establish trust between a factory-fresh device, and a controller with no human involved, so TP-Link used different shortcuts: from hard-coded keys and certificates shared across multiple devices, to default credentials, and from guessable serial numbers as “identity”, to weak session-key randomness.

Now, Forescout says 15 vulnerabilities its researchers discovered all allow for different ways of exploiting these shortcuts, meaning a flaw anywhere in the onboarding chain can compromise every device that goes through it. These bugs would need to be combined with two previously disclosed command-injection flaws, though.

“The vulnerabilities fall into four impact categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications,” Forescout said. “Combined with two previously disclosed CVEs (CVE-2025-7850 and CVE-2025-7851), these flaws enable concrete attacks that let attackers infiltrate networks through controllers and client devices.”

Out of the 15 discovered flaws, 11 received CVE identifiers, and the rest did not receive a tracking number.

Forescout said there are more than 1,800 Omada controllers accessible from the wider internet. If you are using any of the devices from the platform, you should head over to TP-Link’s download portal and grab the latest firmware for your device model.

Leave a Reply

Your email address will not be published. Required fields are marked *