CVE Tools
Back to feed
Research Omada zero-day VIGI IP Cameras TP-Link rce

Уязвимости в ZTP TP-Link Omada приводят к полной компрометации сети

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Security researchers at Forescout have disclosed 15 vulnerabilities within the zero-touch provisioning (ZTP) mechanism of TP-Link Omada corporate networking products. These flaws include hardcoded cryptographic keys and insecure certificate validation, which enable man-in-the-middle attacks and unauthorized device enrollment.

When chained with previously reported remote code execution bugs CVE-2025-7850 and CVE-2025-7851, attackers can achieve root-level access to managed switches, gateways, and access points without initial network entry. The research highlights risks spanning Omada controllers and devices, as well as related VIGI IP Cameras, Festa routers, and Tapo/Kasa smart home devices.