• Sources: report, discussion
  • Summary: TP-Link patched 15 flaws Forescout reported in Omada zero-touch provisioning. Eleven carry CVEs (CVE-2025-9289 through CVE-2025-9293, CVE-2025-15544, CVE-2025-15627 through CVE-2025-15631) and chain with CVE-2025-7850 and CVE-2025-7851 to reach remote code execution. The remaining four received no tracking number and are described as design-level findings: serial-number-only adoption, default credentials at initial adoption, predictable serials, and unauthenticated temporary download links. The affected surface named in the report is Omada controllers, gateways, switches, access points and OLT platforms, plus Omada cloud services and TP-Link mobile applications, with some flaws also reaching IP cameras, smart home IoT devices and cloud accounts. The report directs users to TP-Link's Omada download portal and names no firmware versions, so fixed versions are not yet known from this run. Forescout reports over 1,800 internet-accessible Omada controllers, and neither Forescout's own write-up nor TP-Link's advisory resolved from this run, so this entry rests on the BleepingComputer report.
  • Why it matters: Four of the 15 findings carry no tracking number, so a team that tracks this by CVE list alone sees 11 items and misses the design-level findings on adoption.
  • Follow-up: Track Forescout's own write-up and a TP-Link advisory with affected firmware versions.

send feedback on this story