Omada’s Provisioning Plane Is the Real Attack Surface
Omada’s zero-touch provisioning is the trust boundary, so a compromise there can reach far beyond one bad controller or gateway. The standard fix-it response — patch the exposed device — misses that the attacker may be riding the setup path the fleet already trusts, which can open initial access and lateral movement across enrolled devices.
Forescout says it found 15 Omada provisioning flaws, including CVE-2025-7850 and CVE-2025-7851, and showed they can be chained with earlier bugs. The result can include credential theft, device spoofing, and root shell access on the underlying operating system, with the attack coming from what looks like the trusted perimeter. TP-Link has released staged mitigations, and researchers said about 1,800 controllers were visible online.
The forward risk is the same trust model itself: if centralized enrollment is part of deployment, one break in the provisioning chain can turn fleet management into fleet compromise. Traditional detection may miss it because the activity arrives through channels administrators normally allow.