Security Advisory: Response to Research Concerning TP Link Zero Touch Provisioning (ZTP) Technologies

Security Vulnerability
08-03-2026

Overview

TP‑Link is aware of security research by Forescout Research – Vedere Labs scheduled for presentation at Black Hat USA 2026 and DEF CON 34 regarding multiple vulnerabilities and security observations affecting certain TP‑Link device management and Zero‑Touch Provisioning (ZTP) technologies.

The research discusses vulnerabilities affecting portions of the Omada ecosystem and related technologies used across selected TP‑Link product families. TP‑Link worked with the researchers through a coordinated vulnerability disclosure process to investigate and address the reported issues. Security updates and mitigations have been released in multiple stages throughout the coordinated disclosure process, as vulnerabilities were internally verified and remediated. Affected security advisories were published prior to, or concurrent with, public disclosure of the research.

This advisory provides a consolidated view of the findings discussed in the research and links to individual security advisories for vulnerabilities assigned CVE identifiers.

Summary of Findings

The research describes multiple issues involving:

  • Device adoption and provisioning workflows
  • Authentication and credential handling
  • Cryptographic trust relationships and certificate validation
  • Device and controller communications
  • Cloud and controller management interfaces

Several findings required a combination of conditions to achieve the attack scenarios described by the researchers. The reported attack chains generally require successful exploitation of multiple weaknesses rather than relying on a single vulnerability.

Vulnerabilities Addressed Through Individual Security Advisories

TP‑Link has issued or is issuing individual security advisories for the following CVEs:

Previously Published Advisories (CVE-2025-7850, CVE-2025-7851, CVE-2025-9289, CVE-2025-9290, CVE-2025-9292, CVE-2025-9293)

Newly Published Advisories

  • CVE‑2025‑9291
  • CVE‑2025‑15544
  • CVE‑2025‑15627
  • CVE‑2025‑15628
  • CVE‑2025‑15629
  • CVE‑2025‑15630
  • CVE‑2025‑15631

Customers should consult the corresponding individual advisories for affected models, impacted firmware versions, severity ratings, and remediation guidance.

Additional Security Findings

The research also discusses several findings that were evaluated separately from the CVE process:

Reference

Description

FSCT‑2025‑0003

Device adoption may rely on knowledge of a device serial number during initial onboarding

FSCT‑2025‑0008

Initial device adoption authentication relies on default credentials

FSCT‑2025‑0011

Device information enumeration through predictable serial number sequences

FSCT‑2025‑0014

Uploaded files may be retrievable through generated download links under certain conditions

These items were reviewed as part of TP‑Link's post-release monitoring and product security assessment process. While they are discussed in the research, they were not assigned CVE identifiers. TP‑Link includes them here for completeness and transparency.

Affected Products

The findings discussed in the research primarily affect portions of the Omada ecosystem and related technologies, including selected:

  • Omada Controllers
  • Omada Gateways
  • Omada Switches
  • Omada Access Points
  • Omada OLT platforms
  • Omada Cloud services
  • TP‑Link mobile applications
  • Selected related platforms and product families using shared provisioning or trust components

Customers should refer to individual security advisories and Omada download center for model‑specific information.

Customer Impact

The research demonstrates potential attack scenarios involving combinations of multiple vulnerabilities affecting device onboarding workflows, controller trust relationships, credential handling, cloud communications, and management interfaces. Successful compromise in the attack scenarios described by the researchers depends on chaining multiple vulnerabilities together rather than exploiting a single issue in isolation.

The practical impact of an individual vulnerability may vary depending on deployment architecture, controller type, network position of the attacker, product configuration, and whether affected devices are undergoing provisioning or management operations at the time of the attack. Some scenarios described in the research also rely on limited adoption or onboarding workflows, specific network access conditions, or the ability to intercept or influence communications between devices and controllers.

Customers should review the individual CVE advisories for vulnerability-specific impact information and ensure that all available updates are applied to affected controllers, devices, applications, and cloud-managed environments.

Mitigation and Remediation

TP‑Link recommends that customers:

  1. Update all affected devices to the latest available firmware releases.
  2. Update all Omada controllers and associated management software.
  3. Update affected mobile applications to the latest available versions.
  4. Enable multi‑factor authentication on TP‑Link cloud accounts whenever available.
  5. Use strong and unique administrative credentials.
  6. Rotate credentials, VPN secrets, and certificates where appropriate.
  7. Follow network segmentation and defense‑in‑depth best practices.
  8. Review product firmware and software download center and apply all recommended security updates.

TPLink Commitment to Security

TP‑Link appreciates the efforts of the security research community and values responsible coordinated vulnerability disclosure. We remain committed to investigating reported vulnerabilities, developing appropriate mitigations, and providing timely security guidance to customers.

Acknowledgement

TP‑Link thanks Forescout Research – Vedere Labs, including Stanislav Dashevskyi and Francesco La Spina, for reporting these issues and for working through a coordinated disclosure process. The reported findings were investigated and addressed according to TP‑Link's vulnerability handling processes and policies.

Disclaimer:

This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.

Please Rate this Document