Forescout disclosed 15 vulnerabilities in TP-Link’s Omada zero-touch provisioning ecosystem that can be chained to compromise managed device fleets, hijack controllers and devices, and potentially take over entire networks. The flaws span hardcoded cryptographic material, insecure credential transmission, weak certificate validation, a cloud adoption race condition, cross-site scripting, predictable serial numbers, and default credentials; 11 received CVE identifiers. Researchers said the chain can be combined with previously disclosed remote code execution bugs CVE-2025-7850 and CVE-2025-7851 to achieve administrative control and possible root-level command execution on Omada devices, while identifying roughly 1,800 internet-exposed Omada controllers.
One of the disclosed issues, CVE-2025-15628, carries a CVSS 4.0 score of 8.2 and involves hardcoded certificates shared across Omada deployments, creating a path for attackers who obtain the certificates to impersonate trusted controllers or devices and intercept communications. TP-Link’s advisory portal shows broad ongoing remediation activity across Omada and other product lines, and the company has issued patches and advisories for some of the newly reported weaknesses; however, some structural fixes are not expected until later in 2026 and certain lower-severity issues will remain unpatched. Researchers also warned that related weaknesses may extend beyond Omada to other TP-Link families including VIGI, Festa, Tapo, and Kasa.

See affected versions and whether adversaries are exploiting it.
35 events from the most recent confirmed update back to the earliest known activity.
A vulnerability entry for CVE-2025-15628 was published describing hardcoded certificates in TP-Link Omada device communications. The issue could allow attackers who obtain the embedded certificates to impersonate trusted controllers or devices and intercept communications.
According to Forescout's disclosure, TP-Link issued patches and advisories for part of the reported Omada zero-touch provisioning issues. TP-Link also said some structural fixes may not be completed until later in 2026 and some low-severity issues will remain unpatched.
Forescout found approximately 1,800 Omada controllers accessible from the public internet and warned that these controllers should not be exposed online. The researchers also said similar weaknesses extend to other TP-Link lines including VIGI, Festa, Tapo, and Kasa.
Forescout showed that newly disclosed Omada weaknesses could be chained with previously disclosed CVE-2025-7850 and CVE-2025-7851 to intercept credentials, hijack controllers or devices, gain administrative control, and potentially achieve root-level command execution. The attack scenarios included both external and local-network attackers.
Forescout disclosed 15 vulnerabilities in TP-Link Omada zero-touch provisioning systems, including hardcoded cryptographic material, insecure credential transmission, weak certificate validation, a cloud adoption race condition, and XSS. The researchers warned that chaining the flaws could compromise managed device fleets and potentially entire networks.
TP-Link published a security advisory for TP-Link Tapo C520WS covering CVE-2026-34118 through CVE-2026-34122 and CVE-2026-34124. The advisory reports multiple vulnerabilities affecting the camera.
TP-Link published a security advisory for CVE-2026-4346 affecting TL-WR850N. The flaw allows cleartext storage of administrative and Wi-Fi credentials via an accessible serial interface.
TP-Link published a security advisory for CVE-2026-3622 affecting TL-WR841N. The vulnerability is a denial-of-service issue in the UPnP component.
TP-Link published a security advisory for CVE-2026-3841 affecting TL-MR6400. The issue is a command injection vulnerability in the device's Telnet CLI.
TP-Link published a security advisory for CVE-2026-1457 affecting VIGI C385. The flaw is an authenticated remote code execution vulnerability caused by a buffer overflow.
TP-Link published a security advisory for CVE-2026-1571 affecting Archer C60. The vulnerability is a reflected cross-site scripting flaw.
TP-Link published a security advisory for CVE-2026-1668 affecting multiple Omada switches. The issue is described as an input validation vulnerability.
TP-Link published a security advisory for CVE-2026-3227 affecting TL-WR802N, TL-WR841N, and TL-WR840N. The issue is an authenticated command injection vulnerability.
TP-Link published a security advisory for Archer AX53 covering CVE-2026-30814, CVE-2026-30815, CVE-2026-30816, CVE-2026-30817, and CVE-2026-30818. The advisory reports multiple newly tracked vulnerabilities in the device.
TP-Link published a security advisory for Archer BE230 covering CVE-2026-22220 and CVE-2026-22228. Both vulnerabilities are described as denial-of-service issues.
TP-Link published a security advisory covering authenticated command injection vulnerabilities affecting Archer BE230, Archer AXE75, and Deco BE25 under CVE-2026-0630, CVE-2026-0631, CVE-2026-22221 through CVE-2026-22227, and CVE-2026-22229. The disclosure spans multiple TP-Link product lines.
TP-Link published a security advisory for CVE-2026-0629 affecting VIGI cameras. The issue is an authentication bypass in the password recovery feature via a local web application.
TP-Link published a security advisory for CVE-2026-0620 affecting Archer AXE75. The flaw causes L2TP over IPSec encryption failure.
TP-Link published a security advisory for Deco BE25 covering CVE-2026-0654, CVE-2026-0655, and CVE-2026-22229. The issues include command injection and path traversal vulnerabilities.
TP-Link published a security advisory covering Tapo C260, D235, and C520WS vulnerabilities tracked as CVE-2026-0651, CVE-2026-0652, and CVE-2026-0653. The disclosure affects multiple Tapo camera models.
TP-Link published a security advisory for CVE-2025-7375 affecting Omada EAP610. The issue is described as an unauthenticated denial-of-service vulnerability.
TP-Link published a security advisory covering multiple Archer AX53 flaws, including CVE-2025-58455, CVE-2025-59482, CVE-2025-59487, CVE-2025-62404, CVE-2025-61944, CVE-2025-61983, CVE-2025-62405, CVE-2025-58077, CVE-2025-62673, and CVE-2025-62501. The disclosure identifies a broad set of vulnerabilities affecting the router.
TP-Link published an Omada security advisory covering CVE-2025-9291, CVE-2025-15544, and CVE-2025-15627 through CVE-2025-15631. The disclosure adds a separate set of multiple vulnerabilities affecting TP-Link Omada devices.
TP-Link published a security advisory titled 'Multiple Vulnerabilities in Omada Controllers' covering CVE-2025-9520, CVE-2025-9521, and CVE-2025-9522. The advisory groups several controller vulnerabilities into a single disclosure.
TP-Link published advisories for CVE-2025-9292 and CVE-2025-9293. These cover a permissive web security policy issue in Omada Cloud Controllers and insufficient certificate validation in multiple TP-Link mobile applications.
TP-Link published advisories for CVE-2025-9289 and CVE-2025-9290 affecting Omada products. The issues include cross-site scripting in Omada Controllers and an authentication weakness affecting Omada Controllers, Gateways, and Access Points.
TP-Link published a security advisory stating that Omada Controller is exposed to MongoBleed under CVE-2025-14847. The advisory adds a new Omada-related vulnerability to TP-Link's disclosures.
TP-Link published a security advisory for CVE-2025-15545 affecting Archer RE605X. The issue involves insufficient input validation in backup file upload handling.
TP-Link published a security advisory for CVE-2025-15606 affecting TD-W8961N. The vulnerability is a denial-of-service issue in HTTPD input handling.
TP-Link published a security advisory for CVE-2025-15568, a command injection vulnerability affecting Archer AXE75. The advisory identifies the flaw as enabling command injection on the device.
TP-Link published a security advisory for CVE-2025-15557 affecting Tapo H100 and P100. The issue is improper certificate validation that could enable a man-in-the-middle attack.
TP-Link published a security advisory for CVE-2025-15551, a LAN code execution issue affecting Archer MR200, Archer C20, TL-WR850N, and TL-WR845N. The flaw allows code execution from the local network.
TP-Link published a security advisory for TP-Link VX800v covering CVE-2025-13399, CVE-2025-15541 through CVE-2025-15543, and CVE-2025-15548. The advisory identifies multiple flaws affecting the VX800v product line.
TP-Link published a security advisory covering Archer NX200, NX210, NX500, and NX600 vulnerabilities tracked as CVE-2025-15517 through CVE-2025-15519 and CVE-2025-15605. The issues affect multiple NX-series devices.
TP-Link published a security advisory for CVE-2023-50224 affecting legacy TP-Link router and access point products. The advisory is listed on TP-Link's security advisory index.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
16 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecyberveille.ch
Open sourcehackread.com
Open sourcedarkreading.com
Open sourcecvefeed.io
Open sourcesupport.omadanetworks.com
Open sourcetp-link.com
Open sourcetp-link.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.