Researchers identified a vulnerability in TP-Link Omada routers where sequentially guessable serial numbers printed on device packaging can be submitted to the Omada cloud service to retrieve the device's MAC address and model, forming part of an attack chain that could lead to device hijacking and traffic interception.
TP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a guessed one to the Omada cloud service returns the matching device’s MAC address and model. Serials beginning 22460J500 appear to be ER605 routers, and serials beginning 224608100 appear to be the ER7206. Forescout’s Vedere Labs researchers built that into an attack chain, one of several they assembled … More → The post 15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic appeared first on Help Net Security .