Forescout's Vedere Labs researchers disclosed 15 vulnerabilities in TP-Link's Omada SDN ecosystem at Black Hat USA 2026, using them as a case study to highlight systemic risks in zero-touch provisioning (ZTP). The bugs span device hijacking, client-side code execution, sensitive data disclosure, and encryption weaknesses. A key attack scenario shows how predictable sequential serial numbers combined with a race condition allow an external attacker to impersonate a device, authenticate with default credentials, obtain cleartext secrets, and move laterally. The researchers argue ZTP's convenience collapses many trust decisions into a single automated flow, creating a high-value attack target. They recommend treating ZTP as 'Zero-Trust Provisioning' with strong segmentation, secret hygiene, and threat modeling rather than assuming the technology is inherently safe.