Executive brief
TP-Link Omada networking devices use a weak hashing algorithm to protect administrator and site credentials stored in the device or management environment. An attacker who gains access to the stored credential hashes (through device compromise, database theft, or backup extraction) can crack them offline to recover plaintext credentials, leading to unauthorized administrative access and compromise of the entire network.
Technical details
This vulnerability stems from the use of a legacy or insufficient cryptographic hashing algorithm for protecting site credentials in Omada devices and their management systems. Rather than using modern password hashing schemes (e.g., bcrypt, scrypt, Argon2), the implementation allows attackers to brute-force or rainbow-table attack stored credential hashes with modest computational effort. The attack requires prior access to the credential storage—either through device filesystem access, database exfiltration, or backup file theft—but does not require authentication to the device or network access. Once credentials are recovered, an attacker gains full administrative control of affected Omada infrastructure.
Affected products
- TP-Link Omada <UNKNOWN>
- TP-Link Deco <UNKNOWN>
Timeline
- 2026-08-03: disclosed