TP-Link Omada Hit by Chain Attack

Does your enterprise network rely on cloud-managed TP-Link Omada devices?
Fifteen chained vulnerabilities threaten complete control of your infrastructure.
The Omada ZTP system configures routers, switches, and access points from a central controller — a convenience that now becomes a critical attack vector.
Forescout demonstrated that combining several flaws with two previously known remote code execution vulnerabilities allows an external attacker to seize full command.

The attack begins before anyone plugs in a cable.
During cloud device adoption, a race condition exists that an attacker can exploit from the internet, with no prior network access. By leveraging it, they intercept credentials and configuration data, ultimately gaining administrative control over the cloud controller account. From there, they have an open door into the corporate network — without ever setting foot on the premises.
A single compromised controller governs the entire fleet.
From inside the local network, an attacker can impersonate a legitimate controller or device, intercept credentials, decrypt protected traffic, or gain unauthorized access. In some cases, all it takes is for an administrator to approve a spoofed device. The result can be root-privileged command execution across all managed Omada devices.
Forescout found 1,800 Omada controllers directly exposed to the internet with no protection.
Those controllers should not be reachable from the web, yet there they are. Eleven of the fifteen flaws have assigned CVEs. The remaining four were dismissed by TP-Link as low severity. Some patches are already available, but the more structural fixes will not arrive until late 2026.

Not all promised patches will arrive soon.
While you wait for those fixes, the risk remains active. The flaws include cryptographic keys hardcoded in firmware, insecure credential transmission, weak certificate validation enabling man-in-the-middle attacks, and predictable serial numbers that facilitate device enumeration and hijacking.
The problem goes far beyond Omada.
Forescout confirmed that the same weaknesses recur across other TP-Link product lines. The VIGI IP camera platform, Festa routers, and the Tapo and Kasa smart home lines share these underlying issues. The exposed surface thus extends well beyond enterprise environments, reaching home installations and small businesses that rely on these devices every day.
The findings were presented at Black Hat Las Vegas this week.
Forescout presented the results at the Black Hat conference in Las Vegas, one of the most widely followed cybersecurity events in the world. That public visibility increases pressure on TP-Link to accelerate pending patches, but it also alerts potential attackers to exactly where to look.

CVE-2025-7850 and CVE-2025-7851 are the key that activates the chain.
These two already-known remote code execution CVEs are what turn the new flaws into a complete attack chain. Without them, the risk would be lower. With them, researchers demonstrated practical, reproducible attack paths leading to full control.
Act now — don’t wait until 2026.
Apply the patches TP-Link has already released for the CVE-assigned flaws. Ensure no Omada controller is exposed to the internet — if one is, take it offline immediately. Change default credentials on all affected devices and verify whether your VIGI, Tapo, or Kasa product lines also require updates.
Your network is only as strong as its controller.
If an attacker takes that controller, they have everything. The question is not whether these flaws are exploitable, but when someone will try it against you.
What to do now
- ✓Update your Omada controllers immediately with the patches available from TP-Link.
- ✓Verify that no Omada controller has direct exposure to the internet.
- ✓Change default credentials on all your affected TP-Link devices.
Do you know how many of your TP-Link devices are actually exposed right now?
Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.
Related articles
Nacata Security, reach out to us anytime
We are Nacata Security, get to know us
web: nacata.io
email: info@nacata.io
Phone: 919930793
LinkedIn: Nacata Security
Risks and attacks happening right now: vulnerabilities being actively exploited, official alerts from cybersecurity agencies, ongoing phishing or malware campaigns.
Information meant to help you act and protect yourself before the problem reaches you.
RATING
7.5
Who are we?
At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.
We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.
We’d be glad to get in touch with you for whatever you need.




