Black Hat USA: TP-Link Flaws Put Omada Controllers and Camera Feeds at Risk
A TP-Link network device that had not yet completed registration could be impersonated during setup, allowing an attacker to obtain configuration data, VPN keys, and management credentials. The scenario is one of several attack chains built from 15 newly disclosed flaws in TP-Link’s Omada zero-touch provisioning ecosystem.
Presented by Forescout Research’s Vedere Labs at Black Hat USA 2026, the findings affect selected Omada controllers, gateways, switches, access points, optical line terminals and mobile applications. Selected TP-Link products that use shared cloud, provisioning, or certificate components are also affected.
How Zero-Touch Provisioning Became an Attack Route
Zero-touch provisioning allows a company to connect a new router, switch or access point and have it configured automatically by a central controller. During that process, the device receives network settings, administrative credentials, VPN information and firmware updates.
Forescout foundweaknesses in the way Omada devices identify controllers, protect credentials and establish encrypted...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE