TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices
- Forescout’s Vedere Labs found 15 flaws in TP‑Link Omada business networking gear, exploitable for RCE when chained with prior CVEs
- Weak trust shortcuts in zero‑touch provisioning exposed devices to client‑side code execution, hijacking, spoofing, and encrypted comms compromise
- TP‑Link released firmware updates; admins should patch immediately, with 1,800+ Omada controllers exposed online
TP-Link has patched more than a dozen vulnerabilities across multiple business networking products which could have been chained to achieve remote code execution (RCE).
Security researchers at Vedere Labs from Forescout found the flaws and published an in-depth report on the issues, which particularly affect TP-Link Omada, the company’s business networking platform for centrally managing enterprise and small-business network infrastructure.
It includes cloud-managed Wi-Fi access points, routers, switches, gateways, and controllers, all of which can be monitored and configured from a single interface.
Enabling "concrete attacks"
These support zero-touch provisioning (ZTP), a mechanism that allows IT managers...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE