TP-Link Omada Chain Steals Admin Logins via Fake Pop-Up

Help Net Security · High sophistication
Last updated August 5, 2026

Researchers demonstrated an attack chain against TP-Link Omada where attackers can claim a device in the cloud using guessed serial numbers and default factory credentials. The attacker can then inject a fake “session expired” login prompt into the admin’s browser to steal the cloud controller password and potentially create a VPN tunnel into the victim’s internal network. The issues affect Omada and also extend to other TP-Link product families that share the same certificate trust chain.

Key findings

  • Sequential device serial numbers can be guessed and queried to retrieve matching device details from the cloud service.
  • Attackers can race device adoption by spoofing a MAC address and using factory credentials (admin/admin) to complete the authentication challenge.
  • The cloud can return site credentials (including a site username in cleartext and a site password as an unsalted MD5 hash), and the protocol may accept the hash as proof of identity.
  • A firmware version field is not sanitized; JavaScript placed there can execute in the administrator’s browser and be used to display a fake login box to steal credentials.
  • Once in the controller account, attackers can configure VPN tunnels into the internal network; the article also cites a root command execution flaw (CVE-2025-7850) on devices once inside.
  • Omada controllers ship with a baked-in TLS certificate/private key; if extracted, attackers can impersonate a controller, and similar trust issues affect VIGI, Festa, Tapo, and Kasa product families.

Who’s being targeted

  • Commonly targeted roles: IT, Network administrators, Security operations, Facilities / Physical security (camera admins).
  • Affected industries: Small and medium businesses (SMBs) using TP-Link Omada, IT / Network operations teams, Physical security / camera deployments (VIGI), Consumer / smart home deployments (Tapo, Kasa).
  • Attack channels: website.
  • Impersonated: Omada dashboard / cloud controller login.

Awareness takeaways

  • Treat unexpected re-login prompts inside admin consoles as suspicious; verify by navigating to the known login page rather than typing credentials into pop-ups/overlays.
  • Do not rely on shared passwords across many devices; use unique credentials and rotate them after provisioning.
  • Turn on multi-factor authentication (MFA) for cloud management accounts to reduce the impact of stolen passwords.
  • Prioritize patching controllers and management apps first, since compromise of the controller can expose all managed devices.

Red flags to watch for

  • Unexpected “session expired” box appearing as an overlay inside the admin console
  • Login prompt that does not behave like the normal sign-in flow (embedded over the dashboard)
  • Any re-login prompt that appears immediately after device/provisioning activity or at unusual times
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re in the TP‑Link Omada dashboard, configuring a site, when a “session expired” login box suddenly pops up over the screen. Researchers showed they can claim Omada devices in the cloud, inject JavaScript into a firmware field, and use it to draw this fake session-expired box that sends your password to their server. Here’s the trick: the fake box looks legit and sits right on top of your live dashboard. But Omada normally logs you out with a full-page redirect to the real login screen, not a little pop-up floating over active graphs and devices. If Omada asks you to log in again, don’t trust the pop-up. Close it, go to your normal Omada login URL in a fresh tab, and sign in only there.

Similar attacks

RatHat Lures Users to Install Fake Android Apps

RatHat Lures Users to Install Fake Android Apps

Researchers describe RatHat, an Android trojan linked to China-based operators, that spreads via smishing, malvertising, and fake app stores to trick people into installing a malicious APK. Once installed, it pushes for Accessibility permissions and then uses that access to take deep control of the…

September 18, 2026
Fake ChatGPT Invoice Email Steals Logins

Fake ChatGPT Invoice Email Steals Logins

Attackers are sending fake ChatGPT billing emails that pressure people to “update payment” within 48 hours to avoid service interruption. The message links to a convincing look‑alike ChatGPT login page via a Google redirect, aiming to steal OpenAI credentials.

September 18, 2026
Passkey Helpdesk Scam Hijacks Microsoft Accounts

Passkey Helpdesk Scam Hijacks Microsoft Accounts

Microsoft described two real-world campaigns: an invoice fraud blast impersonating executives to trick finance teams into ACH payments, and a passkey-themed helpdesk scam that steals or bypasses authentication to take over Microsoft cloud accounts. In the second campaign, victims are called or…

September 13, 2026
Fake IT Help-Desk Calls Steal M365 Sessions

Fake IT Help-Desk Calls Steal M365 Sessions

Arctic Wolf reports a wave of phone-based social engineering where attackers pose as internal IT, guide executives through “routine” MFA/passkey setup, and then send a company-branded login link that steals Microsoft 365 credentials and session tokens. Once inside, attackers methodically inventory…

September 8, 2026
BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

Researchers say the “BigBear 2.0” phishing-as-a-service operation stole over 5,100 Microsoft 365 credential records across 461 organizations by capturing passwords and session cookies. The campaign used an adversary-in-the-middle setup to bypass MFA and maintain access, with stolen data sent to…

September 8, 2026
Invisible Unicode Used to Evade Finance Phishing Filters

Invisible Unicode Used to Evade Finance Phishing Filters

Microsoft researchers reported a real, high-volume phishing campaign that used invisible Unicode “tag” characters to break up finance-related lure words (like “funding”) so email filters wouldn’t detect them. The emails looked normal to recipients but contained hidden characters in the underlying…

September 3, 2026