
[CIVN-2026-0396] Multiple Vulnerabilities in Omada ZTP
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Omada ZTP
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Omada Controllers
Omada Gateways
Omada Switches
Omada Access Points
Omada OLT platforms
Omada Cloud services
TP Link mobile applications
Overview
Multiple vulnerabilities have been reported in Omada ZTP, which could allow an attacker to perform remote code execution, device hijacking and spoofing, client-side code execution, gain unauthorized access, disclose sensitive information, or otherwise compromise the targeted system.
Target Audience:
All end-user organizations and individuals using the affected TP-LinkOmadaproducts.
Risk Assessment:
High risk of unauthorized access, execution of arbitrary code or commands, disclosure of sensitive information, authentication and authorization bypass, and compromise of affected systems.
Impact Assessment:
Potential remote code execution, unauthorized access, information disclosure, data compromise, and disruption of affected systems.
Description
Multiple vulnerabilities exist in Omada ZTP due to improper input validation, insufficient access controls, hard-coded cryptographic keys, inadequate certificate validation, weaknesses in device-to-controller communication, insecure cloud management interfaces, and other security flaws.
Successful exploitation of these vulnerabilities could allow an attacker to perform remote code execution, device hijacking and spoofing, client-side code execution, gain unauthorized access, disclose sensitive information, or otherwise compromise the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://support.omadanetworks.com/us/document/130627/
Vendor Information
Omadanetworks
https://support.omadanetworks.com/
References
Omadanetworks
https://support.omadanetworks.com/us/document/130627/
CVE Name
CVE-2025-7850
CVE-2025-7851
CVE-2025-9289
CVE-2025-9290
CVE-2025-9291
CVE-2025-9292
CVE-2025-9293
CVE-2025-15544
CVE-2025-15627
CVE-2025-15628
CVE-2025-15629
CVE-2025-15630
CVE-2025-15631
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp7C4QACgkQ3jCgcSdc
ys/DcQ/9EBwntadzwRsGshHWI3BPEkUBgOAiI2JFc7LhZD3IDgTQ5//ZwsJ8fkOW
ss58u6w14g/Wf8SAdKI4hyDPEmLFIcyv3MF+Rwat2JVdkU9E6BkL7E9covu41m/3
uj46aVugYjiG8ldgK3zbGuO55v9tLrA6en7OwjztTZJuUx/iah/yo6DMa2HBUqpM
rJasA2Qqyi9hVZnmPUTiO8O2LOgTkVrL6n74bC82LD9OCtYgm2nAPlHBW0ANenZe
f8a2XuZ3+TG6H36POnBzR7shYwTP0KAJKYVNtk+jFgU8w4m9YdkM/Fx3dBqwVt2B
qsdZ1MiYV/kb34IpQeLMEz6fzZTy/TNG2W1FM9HPkNrESlfnutEiUxF1qXscbeU6
ar5TV6o9MsTFGRAXkBXlWKi1ZG/6XxTJ3Qxi5RTVoLjVjLePLS5018NEfGWSxlna
9VznjQrKsB/w5fhdE3OjXanbwCyv776d9tV1ePq96LsN9C5ghglS3m+RC3VxnWak
N1u8aCvxiHjE49P1PvWVmpmT/rhRL7E8agzKytv4XGIrasEGUO6bko4doqFdnOKy
biTVj067Ceq+CP8BzzlNZvaphIs7yf2op7T82/kSfWXHBGU17Xe/1P/2fZifITTd
bXfq+D4P2AmypvTfLab2UJ/Dx8s3N+FlHsaCtJxa+4Eb7yCQUqk=
=54ea
—–END PGP SIGNATURE—–


