LAS VEGAS —Researchers have found fifteen previously unknown vulnerabilities that affect zero-touch provisioning in TP-Link Omada, which is widely used to provision network devices from a central location, according to a report by Forescout Research - Vedere Labs. Small to medium-sized companies use the technology to rapidly set up routers and firewalls, which in some cases involves thousands of devices. The technology helps companies save considerable costs when deploying network devices, but it also offers attackers wide access to a lot of systems. The research, presented Wednesday at the Black Hat USA conference in Las Vegas, shows that attackers can chain together vulnerabilities with previously disclosed flaws and infiltrate networks. “The largest risk is that the Omada provisioning and management protocols can be used for initial access and lateral movement by the attackers,” Principal Security Researcher Stanislav Dashevskyi and Senior Security Researcher Francesco La Spina told Cybersecurity Dive via email. They said traditional detection systems may have a hard time detecting such an attack because it comes from the “trusted perimeter.” High risk menu The newly discovered vulnerabilities pose a serious risk to users, and are grouped in four specifics areas: - Client-side code execution through cross-channel scripting - Disclosure of sensitive information, such as passwords and cryptographic keys - Device hijacking and spoofing - Compromising encrypted communications as well as the underlying chain of trust The previously disclosed flaws include a command-injection vulnerability, tracked as CVE-2025-7850 and CVE-2025-7851, which allows an attacker to gain root shell access on the underlying operating system. TP-Link released a security advisory on Monday to address the vulnerabilities. The company said patches and mitigations were released in multiple stages when the flaws were verified and addressed, as part of a disclosure process coordinated with Forescout. The company noted that a successful attack generally required