Overview
- Forescout published detailed research at Black Hat and disclosed 15 zero‑touch provisioning flaws that include hardcoded keys, weak certificate checks, predictable serials, default credentials, a cloud adoption race condition, and cross‑site scripting.
- The researchers showed how several of the new flaws can be chained with two previously disclosed 2025 command‑injection CVEs to achieve remote code execution and reconfigure managed devices.
- Forescout said it found about 1,800 Omada controllers exposed on the public internet, creating real risk for small businesses, managed service providers, and enterprises that rely on remote provisioning.
- TP‑Link has issued patches and advisories covering 11 of the findings but says deeper architectural fixes will continue later in 2026 and that four items flagged as low severity will not be assigned CVEs or fixed.
- Operators are urged to apply available updates, remove controller internet exposure, enable multi‑factor authentication, rotate secrets after suspected compromise, and segment provisioning infrastructure to limit damage.