CVE-2025-7850
CVSS 7.2 HIGH: a command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. EPSS 3% (88th percentile).
Vulnerabilities · 52 days ago
Omada’s zero-touch provisioning is the trust boundary, so a compromise there can reach far beyond one bad controller or gateway. The standard fix-it response — patch the exposed device — misses that the attacker may be riding the setup path the fleet already trusts, which can open initial access and lateral movement across enrolled devices.
Forescout says it found 15 Omada provisioning flaws, including CVE-2025-7850 and CVE-2025-7851, and showed they can be chained with earlier bugs. The result can include credential theft, device spoofing, and root shell access on the underlying operating system, with the attack coming from what looks like the trusted perimeter. TP-Link has released staged mitigations, and researchers said about 1,800 controllers were visible online.
The forward risk is the same trust model itself: if centralized enrollment is part of deployment, one break in the provisioning chain can turn fleet management into fleet compromise. Traditional detection may miss it because the activity arrives through channels administrators normally allow.
CVSS 7.2 HIGH: a command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. EPSS 3% (88th percentile).
CVSS 9.8 CRITICAL: an attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. EPSS 0.7% (50th percentile).
4 sources covering this story
Critical flaws allow hackers to exploit zero-touch provisioning process in TP-Link Omada
Attacks can cause widespread damage to trusted devices and data.
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Researchers are calling attention to the risks inherent in automated network device provisioning, using a leading device manufacturer as a case study.
Fifteen TP-Link Omada vulnerabilities let attackers hijack devices with guessed serial numbers, default credentials and a hard-coded key.
TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover
Forescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem.
Part of the PlainSec briefing for 2026-08-08