CVE Tools
Back to feed
Research TP-Link Omada rce TP-Link supply-chain

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic

Help Net Security·By Mirko Zorz··5 min read
CVE Tools coverage

Researchers from Forescout's Vedere Labs discovered 15 critical vulnerabilities in TP-Link's Omada networking products, enabling remote attackers to hijack routers, steal administrative credentials, and create unauthorized VPN tunnels into internal networks. These flaws affect Omada routers, switches, access points, and even devices in four other TP-Link product lines due to shared certificate chains. Most issues have been patched, though four remain without CVE identifiers and two cannot be fixed via firmware updates. Attackers can exploit predictable serial numbers and flawed authentication mechanisms to bypass security controls and compromise devices at scale.