Researchers at Forescout report 15 newly identified vulnerabilities in the TP-Link Omada networking ecosystem, specifically affecting the zero-touch provisioning (ZTP) mechanism used to onboard devices. The researchers say these weaknesses can be combined (“chained”) with previously disclosed issues, potentially allowing attackers to escalate from initial access to remote code execution (RCE) and full network compromise.

Following the findings, Bleeping Computer reports that TP-Link releases patches addressing the 15 ZTP-related flaws. The coverage describes that the patched issues relate to how ZTP handles provisioning and how the vulnerabilities can be exploited in sequence, ultimately enabling remote takeover under certain conditions.

Across the reports, the core issue is that ZTP—intended to automate device setup—introduces an attack surface that can be abused if an adversary can reach the relevant provisioning pathway or influence the provisioning process. TP-Link’s mitigation aims to prevent the chained exploitation path and reduce the likelihood of RCE in Omada-managed environments. Administrators are generally advised to apply the vendor updates and review exposure related to ZTP.