TP-Link has released security patches for 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices. The flaws could be chained with previously disclosed exploits to enable remote code execution.
The vulnerabilities affect Omada's automated device deployment system, which allows network administrators to configure hardware without manual intervention. By combining the newly patched issues with known exploits, attackers could potentially gain unauthorized access and execute arbitrary code on affected network infrastructure.
ZTP mechanisms are critical targets for threat actors seeking to breach enterprise networks, as they typically operate with elevated privileges during the device initialization phase. TP-Link's patch addresses the attack chain that could compromise network security from the ground up.
The company has not disclosed specific technical details about the flaws or confirmed active exploitation. Users of Omada-enabled devices should apply the patches immediately to prevent potential network compromise. The update is available through TP-Link's official support channels.
This incident underscores the security risks associated with automated provisioning systems and the importance of timely patching across network infrastructure.
A Go-based malware distributed through ClickFix attacks is targeting macOS users to steal cryptocurrency, passwords, and Apple Keychain data. The infostealer campaign combines social engineering with credential harvesting.
A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.
Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.
A critical SQL injection vulnerability in Metabase is being actively exploited in the wild to steal customer data. The zero-day attack has already compromised instances at Framework and Tally.