LOWVulnerability
Global

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

·Source: BleepingComputer

Updated:

Executive Summary

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]

Analysis

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]
Source Attribution

Originally published by BleepingComputer on Aug 4, 2026.

Related Threats

HIGHVulnerability

NVD HIGH: CVE-2026-18854 — A vulnerability has been found in Shandong Hoteam PDM Product Data Management Sy...

A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was

CVE-2026-18854
NIST NVD
MEDIUMVulnerability

CISA's New SBOM Rules Face Old Adoption Problem

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cisas-new-sbom-rules-face-old-adoption-problem-image_small-10-a-32416.jpg" align=right hspace=4><b>New Rules Add Hashes and Licenses - But Critics See Little to Drive Adoption</b><br>The U.S. Cybersecurity and Infrastructure Security Agency, the NSA, the FBI and 15 international partners released updated minimum elements for softw

Bank Info Security
HIGHVulnerability

NVD HIGH: CVE-2026-70619 — Odysseus before commit bf325f6 contains a missing authorization vulnerability th...

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication but omit the admin authorization guard. Attackers can supply an attacker-controlled URL to overwrite the embedding backend persisted in the endpoint con

CVE-2026-70619
NIST NVD