Executive brief
TP-Link Omada Gateways send Dynamic DNS (DDNS) authentication credentials over unencrypted connections to third-party DDNS services. An attacker on the network path between a gateway and its DDNS provider can intercept account credentials or modify DNS records, compromising network accessibility and account security for affected organizations.
Technical details
The vulnerability is an insecure transmission flaw in the DDNS functionality of TP-Link Omada Gateways. Authentication credentials are transmitted over an unencrypted channel (HTTP instead of HTTPS) during communication with external DDNS services. An attacker with network visibility or control over the communication path (via man-in-the-middle positioning, ARP spoofing, DNS hijacking, or ISP-level interception) can passively observe or actively intercept these credentials. Exploitation requires DDNS to be enabled and configured on the device, and attacker access to the network segment between the gateway and the DDNS service endpoint. Successful exploitation allows credential theft, unauthorized DDNS account access, and DNS record modification, potentially redirecting traffic and disrupting service availability.
Affected products
- TP-Link Omada Gateways
Timeline
- 2026-08-20: disclosed