[CIVN-2026-0396] Multiple Vulnerabilities in Omada ZTP

By Published On: August 11, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Omada ZTP


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Omada Controllers 

Omada Gateways 

Omada Switches 

Omada Access Points 

Omada OLT platforms 

Omada Cloud services 

TP Link mobile applications

Overview


Multiple vulnerabilities have been reported in Omada ZTP, which could allow an attacker to perform remote code execution, device hijacking and spoofing, client-side code execution, gain unauthorized access, disclose sensitive information, or otherwise compromise the targeted system.


Target Audience:

All end-user organizations and individuals using the affected TP-LinkOmadaproducts.


Risk Assessment:

High risk of unauthorized access, execution of arbitrary code or commands, disclosure of sensitive information, authentication and authorization bypass, and compromise of affected systems.


Impact Assessment:

Potential remote code execution, unauthorized access, information disclosure, data compromise, and disruption of affected systems.


Description


Multiple vulnerabilities exist in Omada ZTP due to improper input validation, insufficient access controls, hard-coded cryptographic keys, inadequate certificate validation, weaknesses in device-to-controller communication, insecure cloud management interfaces, and other security flaws.


Successful exploitation of these vulnerabilities could allow an attacker to perform remote code execution, device hijacking and spoofing, client-side code execution, gain unauthorized access, disclose sensitive information, or otherwise compromise the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://support.omadanetworks.com/us/document/130627/



Vendor Information


Omadanetworks

https://support.omadanetworks.com/


References


Omadanetworks

https://support.omadanetworks.com/us/document/130627/


CVE Name

CVE-2025-7850

CVE-2025-7851

CVE-2025-9289

CVE-2025-9290

CVE-2025-9291

CVE-2025-9292

CVE-2025-9293

CVE-2025-15544

CVE-2025-15627

CVE-2025-15628

CVE-2025-15629

CVE-2025-15630

CVE-2025-15631




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp7C4QACgkQ3jCgcSdc

ys/DcQ/9EBwntadzwRsGshHWI3BPEkUBgOAiI2JFc7LhZD3IDgTQ5//ZwsJ8fkOW

ss58u6w14g/Wf8SAdKI4hyDPEmLFIcyv3MF+Rwat2JVdkU9E6BkL7E9covu41m/3

uj46aVugYjiG8ldgK3zbGuO55v9tLrA6en7OwjztTZJuUx/iah/yo6DMa2HBUqpM

rJasA2Qqyi9hVZnmPUTiO8O2LOgTkVrL6n74bC82LD9OCtYgm2nAPlHBW0ANenZe

f8a2XuZ3+TG6H36POnBzR7shYwTP0KAJKYVNtk+jFgU8w4m9YdkM/Fx3dBqwVt2B

qsdZ1MiYV/kb34IpQeLMEz6fzZTy/TNG2W1FM9HPkNrESlfnutEiUxF1qXscbeU6

ar5TV6o9MsTFGRAXkBXlWKi1ZG/6XxTJ3Qxi5RTVoLjVjLePLS5018NEfGWSxlna

9VznjQrKsB/w5fhdE3OjXanbwCyv776d9tV1ePq96LsN9C5ghglS3m+RC3VxnWak

N1u8aCvxiHjE49P1PvWVmpmT/rhRL7E8agzKytv4XGIrasEGUO6bko4doqFdnOKy

biTVj067Ceq+CP8BzzlNZvaphIs7yf2op7T82/kSfWXHBGU17Xe/1P/2fZifITTd

bXfq+D4P2AmypvTfLab2UJ/Dx8s3N+FlHsaCtJxa+4Eb7yCQUqk=

=54ea

—–END PGP SIGNATURE—–

Share this article