TP-Link Omada chain turns guessed serial numbers into network takeover

Forescout's Vedere Labs built an attack chain from 15 flaws ending at the admin's cloud controller password.

CSBadmin
2 Min Read

Vedere Labs, the research arm of Forescout, tied together 15 flaws across TP-Link’s Omada SMB networking line to achieve full network compromise. An attacker can obtain the admin’s cloud controller password, the shared per-site credential, and a VPN tunnel into the internal network while never touching the target network directly.

The chain starts with sequential serial numbers printed on router packaging. Guessed serials queried against the Omada cloud return MAC addresses and models. By spoofing the MAC and beating the real device in the adoption race, researchers signed the cloud challenge with factory admin/admin credentials and received the site username in cleartext plus an unsalted MD5 password hash that the Omada protocol itself treats as proof of identity.

A spoofed device then reports an unsanitized firmware string; JavaScript inside it executes in the admin’s browser and paints a fake login screen over the Omada dashboard, capturing the real password. From that account, attackers open VPN tunnels and can invoke CVE-2025-7850 to run commands as root on Omada hardware.

The certificate issue has the longest reach. A TLS key baked into Omada controllers also underpins VIGI cameras, Festa routers, and the Tapo and Kasa smart home lines. Vedere Labs found more than 1,800 internet-reachable Omada controllers. TP-Link patched most of the flaws but declined CVEs for four, and two cannot be fixed in firmware. The researchers reported the findings in June 2025, 426 days before publication.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.