TP-Link Security Flaws Expose Omada Controllers and Camera Feeds at Black Hat USA

www.news4hackers.com-tp-link-security-flaws-expose-omada-controllers-and-camera-feeds-at-black-hat-usa-tp-link-security-flaws-expose-omada-controllers-and-camera-feeds-at-black-hat-usa

15 critical vulnerabilities in TP-Link’s Omada zero-touch provisioning framework were revealed at Black Hat USA 2026, exposing management credentials, VPN keys, and surveillance systems.

15 Critical Vulnerabilities in TP-Link’s Omada Framework

A security research team disclosed 15 critical vulnerabilities in TP-Link’s Omada zero-touch provisioning framework during a presentation at Black Hat USA 2026. These flaws could enable unauthorized access to management credentials, virtual private network (VPN) keys, and internal network resources, while also compromising video surveillance feeds from VIGI cameras. The findings, disclosed by Forescout Research’s Vedere Labs, impact a range of Omada devices including controllers, gateways, switches, access points, optical line terminals, and mobile applications.

Impact on Omada Devices and Surveillance Systems

Key Vulnerabilities and Their Impacts

The vulnerabilities stem from weaknesses in how Omada devices authenticate with controllers, safeguard sensitive data, and establish secure communication channels. Researchers identified issues such as hardcoded cryptographic keys, predictable encryption algorithms, insecure password storage, and insufficient certificate validation processes. Additionally, a race condition during cloud-based device registration creates an opportunity for attackers to intercept and manipulate configuration data.

Root Causes of the Vulnerabilities

Hardcoded Keys and Insecure Practices

Four of the flaws did not receive Common Vulnerabilities and Exposures (CVE) identifiers, while the remaining vulnerabilities include CVE-2025-15544, CVE-2025-15627 through CVE-2025-15631, and CVE-2025-9289 through CVE-2025-9293. One attack scenario involves an adversary exploiting sequential device serial numbers to retrieve associated MAC addresses via TP-Link’s cloud infrastructure. By mimicking a device in the registration phase, the attacker could outpace legitimate hardware and gain access to the controller.

Attack Scenarios and Exploitation Paths

Exploiting Serial Numbers for Access

Once authenticated, the malicious device could extract plaintext usernames, unsalted MD5 password hashes, and VPN credentials. This initial foothold could then be leveraged to escalate privileges and compromise additional systems. Combining these findings with previously disclosed vulnerabilities, such as CVE-2025-7850 and CVE-2025-7851, researchers demonstrated a path to execute arbitrary commands and achieve root access on affected devices under specific conditions.

JavaScript Injection and Credential Theft

Another exploit involved injecting malicious JavaScript into the controller’s web interface through improperly sanitized input during device registration. This could trigger a fake login prompt to capture cloud-based administrative credentials. Certificate validation flaws also extended to TP-Link’s Android applications, including Omada, Omada Guard, Tapo, Kasa, Tether, Deco, and VIGI. These apps relied on a shared trust system that failed to enforce strict certificate checks, potentially allowing man-in-the-middle attacks.

Certificate Validation Flaws in TP-Link Applications

The issue was particularly concerning for VIGI surveillance systems, where an attacker positioned on the same network could impersonate a local video management controller, intercept communications, or disrupt camera feeds. Forescout’s analysis highlighted that over 1,800 Omada controllers were publicly accessible via the Shodan search engine, despite being designed for internal network use. This exposure increases the risk of unauthorized access and exploitation.

Public Exposure and Risk Factors

Forescout’s analysis highlighted that over 1,800 Omada controllers were publicly accessible via the Shodan search engine, despite being designed for internal network use. This exposure increases the risk of unauthorized access and exploitation.

TP-Link’s Response and Mitigation Steps

TP-Link addressed the vulnerabilities through coordinated disclosure, releasing updates in multiple phases. Affected users are advised to apply firmware patches, enable multi-factor authentication for cloud accounts, replace shared provisioning passwords, and rotate exposed VPN keys or credentials. The research team emphasized that while the vulnerabilities could be exploited in controlled environments, no evidence of active malicious use has been confirmed.

Conclusion and Security Implications

The findings underscore the importance of securing automated provisioning systems and validating certificate integrity in IoT and network infrastructure. Researchers stressed the need for organizations to proactively address such vulnerabilities to prevent potential exploitation and ensure the security of their network and surveillance systems.



About Author

en_USEnglish