15 TP-Link Omada Flaws Let Attackers Hijack Your Business Network
Security researchers at Forescout have disclosed 15 vulnerabilities in TP-Link’s Omada networking platform that, when chained together, give attackers a path from the internet straight into your internal network. The findings were presented at Black Hat USA this week, and TP-Link has released patches.
If your business runs Omada access points, switches, gateways, or routers — and a lot of Australian SMBs do — this one needs your attention.
What’s the problem?
The flaws sit in Omada’s zero-touch provisioning (ZTP) system, which is how devices automatically connect to a management controller when they’re first plugged in. Forescout found hard-coded cryptographic keys, predictable serial numbers, and default credentials that an attacker can exploit to impersonate a device, steal its configuration — including cleartext usernames and password hashes — and inject malicious code into the admin dashboard. From there, they can reconfigure managed devices, create VPN tunnels into your network, and run commands on your equipment.
Forescout identified over 1,800 Omada controllers exposed directly to the internet, which is never how they should be deployed.
Why this matters for Australian SMBs
TP-Link Omada is popular with small and mid-sized businesses here because it punches well above its price point — cloud-managed Wi-Fi, switching, and routing without the enterprise price tag. The catch is that these devices often sit on whatever firmware they shipped with. Unlike enterprise gear with centralised patch orchestration, Omada kit in a small office or retail site tends to get set up once and forgotten. That’s exactly the kind of environment where these flaws go unpatched for months.
What to do now
Visit TP-Link’s Omada download portal and grab the latest firmware for every device model you run — access points, switches, gateways, the lot. Change your controller’s admin credentials if you’ve never updated them from the defaults. Enable multi-factor authentication on the controller. And if your Omada controller is accessible from the internet, fix that immediately — it should only be reachable from your internal network or via VPN.
If you’re not sure what firmware your gear is running or whether your controller is exposed, get in touch — this is exactly the kind of thing a managed IT provider should be handling for you so nothing slips through the cracks.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
