Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.
August 5, 2026
Black Hat USA 2026 – Las Vegas – Researchers disclosed 15 vulnerabilities in TP-Link networking technologies that they say call into question organizations' blind trust in zero-touch provisioning (ZTP).
TP-Link is one of the world's largest edge device manufacturers. According to the company, its products are used by 1.7 billion people in more than 170 countries. In years past, TP-Link has enjoyed billion-dollar annual sales figures, with somewhere between 15% and 45% of the global market share for wireless local area network (WLAN) tech. The company has even had to play down its ubiquity in recent years, for political purposes.
At Black Hat this week, Forescout's Vedere Labs security researchers Stanislav Dashevskyi and Francesco La Spina revealed 15 vulnerabilities affecting TP-Link "Omada" — the software-defined networking (SDN) ecosystem for TP-Link's routers, switches, gateways, and Wi-Fi access points. The issues aren't so much about the devices, though, as they are the process of onboarding and provisioning them. That's why, more than any specific vulnerability or exploit chain, the researchers are calling attention to ZTP, the trendy and convenient process by which organizations set up their TP-Link tech in the first place.










