Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

TP-Link Omada networking vulnerabilities — patch your routers, switches, and access points now

15 TP-Link Omada Flaws Let Attackers Hijack Your Business Network

Security researchers at Forescout have disclosed 15 vulnerabilities in TP-Link’s Omada networking platform that, when chained together, give attackers a path from the internet straight into your internal network. The findings were presented at Black Hat USA this week, and TP-Link has released patches.

If your business runs Omada access points, switches, gateways, or routers — and a lot of Australian SMBs do — this one needs your attention.

What’s the problem?

The flaws sit in Omada’s zero-touch provisioning (ZTP) system, which is how devices automatically connect to a management controller when they’re first plugged in. Forescout found hard-coded cryptographic keys, predictable serial numbers, and default credentials that an attacker can exploit to impersonate a device, steal its configuration — including cleartext usernames and password hashes — and inject malicious code into the admin dashboard. From there, they can reconfigure managed devices, create VPN tunnels into your network, and run commands on your equipment.

Forescout identified over 1,800 Omada controllers exposed directly to the internet, which is never how they should be deployed.

Why this matters for Australian SMBs

TP-Link Omada is popular with small and mid-sized businesses here because it punches well above its price point — cloud-managed Wi-Fi, switching, and routing without the enterprise price tag. The catch is that these devices often sit on whatever firmware they shipped with. Unlike enterprise gear with centralised patch orchestration, Omada kit in a small office or retail site tends to get set up once and forgotten. That’s exactly the kind of environment where these flaws go unpatched for months.

What to do now

Visit TP-Link’s Omada download portal and grab the latest firmware for every device model you run — access points, switches, gateways, the lot. Change your controller’s admin credentials if you’ve never updated them from the defaults. Enable multi-factor authentication on the controller. And if your Omada controller is accessible from the internet, fix that immediately — it should only be reachable from your internal network or via VPN.

If you’re not sure what firmware your gear is running or whether your controller is exposed, get in touch — this is exactly the kind of thing a managed IT provider should be handling for you so nothing slips through the cracks.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →