Black Hat USA: TP-Link Flaws Put Omada Controllers and Camera Feeds at Risk

Black Hat USA: TP-Link Flaws Put Omada Controllers and Camera Feeds at Risk

Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access and affect VIGI camera feeds.

Listen to this article

0:00

Press play to start listening

A TP-Link network device that had not yet completed registration could be impersonated during setup, allowing an attacker to obtain configuration data, VPN keys, and management credentials. The scenario is one of several attack chains built from 15 newly disclosed flaws in TP-Link’s Omada zero-touch provisioning ecosystem.

Presented by Forescout Research’s Vedere Labs at Black Hat USA 2026, the findings affect selected Omada controllers, gateways, switches, access points, optical line terminals and mobile applications. Selected TP-Link products that use shared cloud, provisioning, or certificate components are also affected.

How Zero-Touch Provisioning Became an Attack Route

Zero-touch provisioning allows a company to connect a new router, switch or access point and have it configured automatically by a central controller. During that process, the device receives network settings, administrative credentials, VPN information and firmware updates.

Forescout found weaknesses in the way Omada devices identify controllers, protect credentials and establish encrypted connections. The 15 findings include hard-coded cryptographic keys and certificates, predictable encryption keys, weak password storage, insufficient certificate checks and a race condition during cloud registration.

Four findings did not receive CVE identifiers. The remaining issues include CVE-2025-15544, CVE-2025-15627 through CVE-2025-15631, and CVE-2025-9289 through CVE-2025-9293.

During one demonstrated attack, an outsider could guess sequential device serial numbers and use TP-Link’s cloud systems to retrieve corresponding MAC addresses. The attacker could then pose as a device awaiting registration and repeatedly contact its controller until winning a race against the legitimate hardware.

Once accepted by the controller, the fake device could authenticate using default credentials and receive configuration data. Forescout said this information could include a cleartext username, an unsalted MD5 password hash, and VPN keys.

Attack Chain Could Reach Internal Networks

After obtaining controller credentials, an attacker could manage devices already registered to that controller, configure VPN tunnels into the organization’s internal network, and pursue other weaknesses.

Forescout combined the new findings with CVE-2025-7850 and CVE-2025-7851, two previously disclosed Omada flaws that permit command execution and root access under specific conditions.

Another chain used unsanitized information supplied during device registration to place JavaScript inside the controller’s web interface. When an administrator opened the affected page, the code could display a fake login form and steal cloud-controller credentials.

Several TP-Link Android applications also used weak certificate validation connected to the same trust system. The affected applications include Omada, Omada Guard, Tapo, Kasa, Tether, Deco, VIGI and others that collectively recorded more than 70 million Google Play downloads.

Black Hat USA: TP-Link Flaws Put Omada Controllers and Camera Feeds at Risk

Those download figures do not represent confirmed compromises. Forescout estimated that TP-Link may have between three million and seven million active cloud accounts, but did not say every account was exposed.

Similar certificate problems reached TP-Link’s VIGI surveillance products. In deployments using a local video-management controller, an attacker in the required network position could impersonate that controller, intercept communications or interfere with camera feeds.

Internet exposure adds another concern because Forescout found more than 1,800 Omada controllers accessible online through Shodan. The researchers noted that these controllers are not normally intended to be directly reachable from the internet.

TP-Link said in its official security advisory that the findings were handled through coordinated disclosure and fixes were issued in several stages. The model-specific Omada CVE and update advisory is available here.

Customers should update controllers, managed devices, and mobile applications, enable multi-factor authentication for cloud accounts, replace shared provisioning passwords, and rotate VPN keys or credentials that may have been exposed.

Forescout’s report documents controlled attack scenarios and does not identify malicious exploitation of the vulnerabilities.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts