TP-Link critical authentication bypass - patch available

Skip a couple Starbucks and get a unifi 😁
The new Express is the cheapest all in one
Although technically you could get a cloud gateway ultra and use your old router as a WAP.
Doesn't unifi also had security problem?

My point is anything online and offline cheap will have security issue. It is the job of the network provider to deal with it.
 
Doesn't unifi also had security problem?

My point is anything online and offline cheap will have security issue. It is the job of the network provider to deal with it.
They all have problems, it's just how fast they fix them that matters. Most of the CVE's are pretty low risk for most people, but manufacturers should fix them.
I just had a cheap picture frame turn into a malware bot. Kind of done with cheap Chinese junk.
 
Doesn't unifi also had security problem?

My point is anything online and offline cheap will have security issue. It is the job of the network provider to deal with it.
They had a recent CVE that was immediately patched. They are good at staying on top of this, others? Not so much.
 
Duh. That's why I said it was "a related note". I understand it's not exactly the same. Also, some modems (AIO) do act as ethernet/wifi routers.
Yes, I would say most ISP's, at least up here in the GWN, no longer send you a modem, but a combo modem/gateway AIO device. I have a Bell "Home Hub" for my GPON service that I've had to disable everything on, though I've discovered a 10Gbit SFP+ bypass solution that uses open source firmware to replace the "Home Hub" for firewalls like my UDM that have an SFP+ slot (and you can also use an SFP+ switch if your Edge device doesn't have an SFP+ slot).
 
Doesn't unifi also had security problem?

My point is anything online and offline cheap will have security issue. It is the job of the network provider to deal with it.
Yes
This was the latest just the other week. I know nothing about this stuff other than its all over the place, regardless of brand it seems to me.

"Ubiquiti notes that in recent years its products have been targeted by both state‑sponsored threat actors and cybercriminal groups who have hijacked devices for botnet‑building and operational obfuscation. As an example, the FBI dismantled a botnet of compromised Ubiquiti Edge OS routers in February 2024 that had been used by Russia’s GRU to proxy malicious traffic in attacks against the United States and allied nations"
https://www.truesec.com/hub/blog/vulnerabilities-critical-ubiquiti-unifi-network-application

I think this is the same thing
https://cybernews.com/security/ubiquiti-unifi-network-application-critical-vulnerability/

PS while you are at it, make sure your cell phone is up to date. I know Apple just released iOS 26.4 for security issues.
 
Last edited:
It seems your complaints have been heard, Overkill, though it doesn't affect Canada. The FCC just announced that it has severely curtailed the import of crappy TP-Link and similar Chinese routers due to security concerns....
This thread made me look at my router box. Not that I am concerned but curious.
MY Archer C4000 was made in Vietnam. TP Link USA address is in CA and at the time listed corporate international address is listed in Hong Kong. The router came out in 2018. I purchased in late 2023

EDIT! Well son of a gun! For fun I went into my router and had it check for updates, one is available. I thought for sure that wouldnt happen anymore since it's an older unit that I bought for a killer price 2 years ago.

Cant do it right now, will knock my wife off her work station. I KNOW I have checked in the past, and I can now see the update came out in Sept 2025 which is pretty impressive for a unit was first produced/first came out in 2018
Screenshot 2026-03-26 at 10.24.22 AM.webp
 
Last edited:
This thread made me look at my router box. Not that I am concerned but curious.
MY Archer C4000 was made in Vietnam. TP Link USA address is in CA and at the time listed corporate international address is listed in Hong Kong. The router came out in 2018. I purchased in late 2023

EDIT! Well son of a gun! For fun I went into my router and had it check for updates, one is available. I thought for sure that wouldnt happen anymore since it's an older unit that I bought for a killer price 2 years ago.

Cant do it right now, will knock my wife off her work station. I KNOW I have checked in the past, and I can now see the update came out in Sept 2025 which is pretty impressive for a unit was first produced/first came out in 2018
View attachment 329914
This is the problem with not having automatic updates enabled by default for home users, it has been 6 months since that was released and you are only seeing it now, and only went looking because of this thread.

For fun, I downloaded that firmware release and there are no release notes in the ZIP file, so it doesn't explain what "Enhanced security of device" means in terms of addressing CVE's that affect that hardware.
 
PS while you are at it, make sure your cell phone is up to date. I know Apple just released iOS 26.4 for security issues.

Yeah about that. A bunch of phone companies just obsoleted my iPhone 7 so now I have to spend that $350 to upgrade to something newer, from something that is perfectly functional, all because the fraud prevention mechanism of a newer caller id etc.
 
Yeah about that. A bunch of phone companies just obsoleted my iPhone 7 so now I have to spend that $350 to upgrade to something newer, from something that is perfectly functional, all because the fraud prevention mechanism of a newer caller id etc.
10 years is a hell of a good run!
 
This is the problem with not having automatic updates enabled by default for home users, it has been 6 months since that was released and you are only seeing it now, and only went looking because of this thread.

For fun, I downloaded that firmware release and there are no release notes in the ZIP file, so it doesn't explain what "Enhanced security of device" means in terms of addressing CVE's that affect that hardware.
You’re right I would not have seen it nor would I have looked for it.
I just assumed updates were over for this device. It’s been eight years now not that I owned it, but this model came out in 2018.
So I’m just impressed that there was even something for it.
I know others don’t feel this way, but for me I don’t really care. Nobody is hacking into my system to take advantage of me. They may hack into my system to take advantage of others.
Correct?

I don’t even allow my iPhone to automatically update. This one I did do right away only because sort of like this thread. I just read about it in the last couple days regarding the iPhone.

They can hack all they want. I already know all of my information is out on the dark web everything and I mean everything addresses phone numbers, Social Security numbers you name it.
Every American and people worldwide to me are just a fish in a bowl just like we fish in the sea. It just depends who gets hooked because there’s just too many fish to catch them all.😜

It’s unavoidable as far as your personal information, everybody has it and it’s all to be found whether it’s in state governments, military, federal government, local governments, Department of Motor Vehicles, your local dentist, your local doctor, your local allergist, etc., etc. etc.

That doesn’t mean we shouldn’t take precautions and why I lock my credit and certainly within reason such as keeping devices updated when possible with our question. I do agree I just don’t lose sleep over any of it.
 
I know others don’t feel this way, but for me I don’t really care. Nobody is hacking into my system to take advantage of me. They may hack into my system to take advantage of others.
Correct?
I mean, they absolutely could, hijack the DNS on the unit and send you to sites that look legit to phish your information and then clean-out your accounts.
 
Yeah about that. A bunch of phone companies just obsoleted my iPhone 7 so now I have to spend that $350 to upgrade to something newer, from something that is perfectly functional, all because the fraud prevention mechanism of a newer caller id etc.
I can’t believe you have an iPhone 7😳
You certainly got your use out of it and it’s only reasonable to expect almost 10 model years later that the hardware can’t keep up
 
Yeah about that. A bunch of phone companies just obsoleted my iPhone 7 so now I have to spend that $350 to upgrade to something newer, from something that is perfectly functional, all because the fraud prevention mechanism of a newer caller id etc.
Aren't you tired of having to recharge it every 30 minutes, anyway? :)
 
Back
Top Bottom