Forescout Vedere Labs has discovered 15 previously unknown vulnerabilities in TP-Link's Omada Zero-Touch Provisioning (ZTP) ecosystem. Researchers demonstrated how these flaws can be chained together — spanning client-side code execution, credential disclosure, device spoofing, and cryptographic trust weaknesses — to move from device onboarding to compromising controllers, cloud services, and managed infrastructure. The risk extends beyond Omada to other TP-Link ecosystems including Festa, VIGI, Tapo, and Kasa. Forescout recommends immediate patching, replacing default credentials, enabling MFA, segmenting provisioning infrastructure, and applying Zero Trust principles to device management workflows.
3 Impressions