Security researchers at Forescout have disclosed 15 new vulnerabilities in the zero-touch provisioning (ZTP) systems used by TP-Link’s Omada networking ecosystem, warning that some of the flaws can be chained to compromise entire fleets of managed devices.
The vulnerabilities affect the ZTP protocols that allow routers, switches, and access points to be automatically configured by cloud-based, hardware, or software controllers, a process designed to reduce manual setup for network administrators managing multiple devices.
Forescout’s findings include the use of hardcoded cryptographic keys and certificates, insecure transmission of device and site credentials, weak certificate validation that enables man-in-the-middle attacks, a race condition in cloud-based device adoption, and a cross-site scripting flaw in controller web interfaces.
Researchers also identified issues such as predictable device serial numbers and default credentials that make it easier for attackers to enumerate and hijack devices.
Eleven of the 15 issues have been assigned CVE identifiers. TP-Link declined to assign CVEs to the remaining four, citing low severity.









