CVE-2025-7850
CVSS 7.2 HIGH: a command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. EPSS 3% (88º percentile).
Vulnerabilità · 52 giorni fa
Il punto debole non è il singolo controller esposto, ma il canale di provisioning che decide a chi fidarsi all’ingresso. Se si rompe la zero-touch provisioning di Omada, l’attacco può partire da lì e poi muoversi lateralmente su molti dispositivi già registrati, senza sembrare ostile ai controlli che si fidano del percorso amministrativo.
Forescout ha messo in fila 15 vulnerabilità in TP-Link Omada ZTP e ha spiegato che alcune si possono concatenare con CVE-2025-7850 e CVE-2025-7851 per ottenere accesso iniziale, impersonare controller o dispositivi e arrivare fino al root shell sui sistemi sottostanti. TP-Link ha pubblicato un advisory il 3 maggio e ha distribuito correzioni e mitigazioni in più fasi; i ricercatori hanno anche indicato circa 1.800 controller visibili online, in ambienti che non dovrebbero essere esposti a Internet.
Il rischio non finisce con la singola patch. Finché il provisioning resta un punto di fiducia della flotta, un solo approvazione compromessa può diventare controllo su molti dispositivi, e il traffico può sfuggire alla detection standard perché arriva dal “trusted perimeter”.
CVSS 7.2 HIGH: a command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. EPSS 3% (88º percentile).
CVSS 9.8 CRITICAL: an attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. EPSS 0.7% (50º percentile).
4 fonti che coprono questa storia
Critical flaws allow hackers to exploit zero-touch provisioning process in TP-Link Omada
Attacks can cause widespread damage to trusted devices and data.
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Researchers are calling attention to the risks inherent in automated network device provisioning, using a leading device manufacturer as a case study.
Fifteen TP-Link Omada vulnerabilities let attackers hijack devices with guessed serial numbers, default credentials and a hard-coded key.
TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover
Forescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem.
Part of the PlainSec briefing for 2026-08-08