Executive brief
TP-Link Omada is a network management system that controls and monitors WiFi access points and network devices across corporate and institutional deployments. The system uses embedded certificates shared across all devices to establish secure communication. An attacker who obtains these certificates can impersonate legitimate controllers or devices, intercept sensitive traffic, and potentially compromise the entire managed network.
Technical details
The vulnerability stems from the use of hardcoded, globally-shared embedded certificates across all Omada device deployments to establish trust relationships between controllers and managed devices. An attacker who obtains these certificates (through reverse engineering, firmware extraction, or disclosure) can cryptographically impersonate trusted devices or controllers without authentication. This allows man-in-the-middle attacks to intercept device-to-controller communications, potentially enabling credential theft, configuration changes, or lateral movement within managed networks. The vulnerability requires network access to the Omada network but no user interaction or authentication. Patch or fix availability has not been specified in available documentation.
Affected products
- TP-Link Omada <UNKNOWN>
Timeline
- 2026-08-03: disclosed: Published on NVD