Forescout Uncovers 15 TP-Link Omada Zero-Touch Provisioning Vulnerabilities
- 事件类型
- Vulnerability
- 报告时间
- 2026-08-05 14:46:35
- 被攻击国家/地区
- USA
- 被攻击行业
- Network & Telecommunications
- 被攻击组织
- tp-link
- 被攻击域名
- tp-link.com
- 攻击组织
- None
- 信息来源
- openweb
Original Text
查看原文
原文内容
Forescout's Vedere Labs has disclosed 15 vulnerabilities affecting TP-Link Omada's Zero-Touch Provisioning (ZTP) mechanism. The flaws impact device onboarding, authentication, credential handling, certificate validation, and cryptographic trust. According to the researchers, attackers could chain multiple vulnerabilities to compromise ZTP controllers, cloud services, and managed devices, potentially enabling remote command execution, device hijacking, sensitive information disclosure, spoofing, and broader enterprise network infiltration. TP-Link has released security updates to address the identified issues and recommends users update affected devices immediately.