Back Issues This Week → Calendar → Current Issue → Popular →

All issuesVolume 341, Issue 1IT NewsSecurity

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

Dark Reading, Wednesday, August 5th, 2026

Forescout researchers disclose 15 TP-Link Omada flaws that question blind trust in zero-touch provisioning.

At Black Hat USA 2026, Forescout Vedere Labs researchers Stanislav Dashevskyi and Francesco La Spina revealed 15 vulnerabilities in TP-Link's Omada software-defined networking ecosystem.

The bugs fall into four buckets: device hijacking and spoofing, client-side code execution, information disclosure, and chain-of-trust compromise.

Because TP-Link serial numbers are sequential and predictable, an external attacker could impersonate a device about to be adopted, win a race condition, and authenticate with default admin credentials to obtain cleartext configuration and secrets.

The researchers argue zero-touch provisioning collapses many trust decisions into one automated flow, making the provisioning server a high-blast-radius target.

more →  ·  More from Security →