Executive brief
TP-Link Omada is a network management platform used to configure and oversee WiFi mesh systems and enterprise networking devices. The adoption protocol—which establishes initial trust between controllers and managed devices—relies on hard-coded cryptographic keys that are identical across all deployments. An attacker with network access can exploit this weakness to impersonate legitimate controllers or devices, potentially gaining unauthorized access to device configuration and sensitive network communications during the adoption phase.
Technical details
The vulnerability exists in the Omada adoption protocol's use of hard-coded cryptographic keys to establish trust between controllers and managed devices. Rather than using unique or dynamically negotiated keys, the protocol employs static, shared secrets that are compiled into the software. This allows an attacker with network access to intercept and decrypt adoption-related communications or forge authentication exchanges without legitimate credentials. The attack requires network-level access to the adoption traffic but no authentication to the victim devices. An attacker can impersonate trusted controllers or devices to alter configuration, inject malicious settings, or extract sensitive information during device onboarding.
Affected products
- TP-Link Deco BE85
- TP-Link Deco BE65
- TP-Link Deco BE65 Pro
- TP-Link Deco BE25
- TP-Link Deco BE23
- TP-Link Deco BE25-Outdoor
Timeline
- 2025-08-03: disclosed