TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices
The Omada platform was found to be vulnerable in different ways, but TP-Link has already issued patches.
Forescout's Vedere Labs has uncovered 15 security flaws in TP-Link Omada business networking gear, which, when exploited together, could allow hackers to take control of these devices. Vulnerabilities in the zero-touch provisioning feature of these devices exposed them to client-side code execution, hijacking, spoofing, and compromised encrypted communications.
TP-Link released firmware updates to patch these flaws, but over 1,800 Omada controllers remain accessible online. The vulnerabilities range from hard-coded keys and certificates to weak session-key randomness, allowing attackers to chain the flaws with previously disclosed command-injection issues. These bugs affect multiple aspects of the devices, including client-side code execution, information disclosure, device hijacking, spoofing, and compromise of encrypted communications.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.