Threat Advisory

TP-Link Omada ZTP Flaws Allow Hackers to Breach Networks

Threat: Vulnerability
Targeted Region: United States
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

### Summary

Multiple security vulnerabilities have been identified in the TP-Link Omada Zero-Touch Provisioning (ZTP) ecosystem, affecting controllers, gateways, switches, access points, cloud services, and related management applications. These flaws include information disclosure, client-side code execution, device hijacking, spoofing, weak cryptographic protections, and certificate validation weaknesses. When chained together with two previously disclosed command injection vulnerabilities, attackers can compromise the Omada chain of trust, infiltrate enterprise networks, and achieve remote code execution on managed devices.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

### Summary

Multiple security vulnerabilities have been identified in the TP-Link Omada Zero-Touch Provisioning (ZTP) ecosystem, affecting controllers, gateways, switches, access points, cloud services, and related management applications. These flaws include information disclosure, client-side code execution, device hijacking, spoofing, weak cryptographic protections, and certificate validation weaknesses. When chained together with two previously disclosed command injection vulnerabilities, attackers can compromise the Omada chain of trust, infiltrate enterprise networks, and achieve remote code execution on managed devices.[emaillocker id="1283"]

• CVE-2025-9289 – An information disclosure vulnerability that may expose sensitive provisioning data, facilitating further attacks against Omada deployments.

• CVE-2025-9290 – A weakness in the Zero-Touch Provisioning workflow that could enable attackers to manipulate device onboarding and trust relationships.

• CVE-2025-9291 – An improper certificate validation vulnerability that enables attackers to intercept or manipulate trusted communications within the Omada ecosystem.

• CVE-2025-9292 – A client-side code execution vulnerability that could allow malicious code execution through crafted management interactions.

• CVE-2025-9293 – A device spoofing vulnerability that may allow attackers to impersonate legitimate Omada devices during provisioning.

• CVE-2025-15544 – A cryptographic weakness that may expose sensitive credentials or encrypted communications to unauthorized access.

• CVE-2025-15627 – A vulnerability affecting device authentication that could enable unauthorized device enrollment or management actions.

• CVE-2025-15628 – An information disclosure vulnerability that may expose configuration data or device credentials.

• CVE-2025-15629 – A trust relationship weakness that could allow attackers to interfere with secure provisioning communications.

• CVE-2025-15630 – A vulnerability impacting the integrity of device management communications, potentially enabling unauthorized configuration changes.

• CVE-2025-15631 – A management interface vulnerability that may assist attackers in compromising Omada-managed devices when chained with other flaws.

• CVE-2025-7850 – A command injection vulnerability that can be chained with the newly disclosed ZTP flaws to achieve remote code execution.

• CVE-2025-7851 – A command injection vulnerability that further enables full compromise of Omada devices when combined with the newly disclosed vulnerabilities.

These vulnerabilities present a significant risk to organizations using TP-Link Omada networking products. Successful exploitation could result in unauthorized device onboarding, credential disclosure, controller compromise, remote code execution, and complete network takeover. Organizations should immediately apply TP-Link firmware and software updates, update Omada controllers and mobile applications, rotate credentials and certificates where appropriate, and avoid exposing Omada management interfaces directly to the internet.

RECOMMENDATION:

We recommend you Upgrade to Omada Software Controller 6.0.0.24+, OC200 v1.2.9+, OC300 v1.31.9+, OC400 v1.9.9+, Omada Cloud Controller 6.0.0.100+, and the latest firmware for affected gateways, switches, and access points.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu