Omada Onboarding Flaws Can Hand Over Entire Fleets
A weak onboarding step in Omada is enough to shift control from one device to the whole management plane. The problem is not a single exposed controller or a bad login screen. It is the trust path used to enroll routers, switches, and access points, which can be abused to insert an attacker into the controller’s authority over the fleet.
Forescout disclosed 15 vulnerabilities in TP-Link Omada ZTP. Some can be chained with CVE-2025-7850 and CVE-2025-7851 to steal credentials, impersonate controllers or devices, and reach administrative control of the cloud controller, with some chains ending in root-level command execution on managed devices. TP-Link has not patched all of them yet; some fixes are pushed into 2026 and some low-severity issues will not be remediated.
The risk is bigger than the exposed controller itself. If the onboarding trust breaks, one compromised approval step can cascade into policy control over every enrolled device, and the same pattern matters anywhere centralized enrollment is treated as a harmless setup task.