A newly disclosed 15 vulnerabilities in TP-Link’s Omada ZTP ecosystem that can be chained to hijack devices, expose credentials, compromise controllers, and potentially gain remote code execution on managed network appliances have been discovered by Forescout Research's Vedere Labs ahead of Black Hat USA 2026 This article explores 2026 ztp enables. . ZTP enables administrators to deploy routers, switches, gateways, and wireless access points at scale.
The simplified fleet deployment simplifies security but also creates a high-value trust boundary: compromising it can provide an attacker with a route into an entire managed estate.
Stanislav found that predictable serial numbers, reliance on only knowing the serial number for device adoption, default credentials used during initial setup, and a cloud adoption race condition tracked as CVE-2025-15630 allowed attackers to initiate an adoption handshake with legitimate devices before they were adopted, while spoofing their MAC addresses. With controller administrator access, an intruder can alter configurations across enrolled devices, establish VPN tunnels into an internal environment, and combine the previously disclosed issues with CVE-2025-7850 and CVE-2025-7851. Forescout highlights that related weaknesses also impact Festa devices, VIGI surveillance infrastructure, TP-Link cloud services, and multiple mobile applications, including Tapo, Kasa, Omada, Deco, Tether, and others.
Additionally, TP-Link suggests enabling MFA on TP-Link cloud accounts, using strong unique administrator credentials, rotating passwords, and securing VPN secrets and certificates where exposure is suspected.












