Affected Systems
TP-Link Omada network devices including Controllers, Gateways, Switches, Access Points, OLT platforms, Cloud services, and mobile applications (Omada, Omada Guard, TP-Link apps). Over 1,800 internet-accessible Omada controllers identified. Affects small to medium-sized businesses and enterprise deployments. Related TP-Link IP cameras and smart home IoT devices also impacted.
Exploitation Status
No active exploitation reported. Full technical details disclosed at Black Hat USA 2026. Exploitation requires chaining newly disclosed flaws with two previously disclosed command-injection vulnerabilities (CVE-2025-7850, CVE-2025-7851). Proof-of-concept attack scenarios published by Forescout Vedere Labs.
Business Impact
Attackers can infiltrate business networks by exploiting zero-touch provisioning weaknesses. Attack chain enables device enumeration via predictable serial numbers, credential theft (cleartext usernames, unsalted MD5 hashes, VPN keys), controller compromise, JavaScript injection for admin phishing, VPN tunnel creation into internal networks, and remote code execution on network equipment. Particularly concerning for MSPs managing multiple client networks and organizations with internet-exposed controllers. Omada mobile apps have 1.1 million downloads (Omada/Omada Guard) and TP-Link apps have 3-7 million active accounts, expanding attack surface.
Urgency
🟠Within 24 hours
Recommended Actions
- Update all TP-Link Omada Controllers, Gateways, Switches, Access Points, and OLT platforms to latest firmware from TP-Link Omada download portal immediately
- Update Omada, Omada Guard, and all TP-Link mobile applications to latest versions on Android and iOS
- Verify Omada controllers are not directly exposed to the internet; place behind firewall with VPN access only
- Rotate all administrator credentials, VPN keys, and secrets on Omada devices; enforce strong unique passwords and enable multi-factor authentication
- Monitor network traffic for unauthorized device adoption attempts, unexpected VPN tunnel creation, and anomalous controller API activity
