Tplink Download Center Patched • Limited Time
Even if the Download Center is now secure, your router might still be vulnerable. Threat actors are actively scanning for TP-Link devices running firmware that was downloaded before the May 2024 patch. Why? Because those older files were never validated.
If you downloaded firmware for your Archer AX55 in April 2024, there is a non-zero chance that file was tampered with in transit. TP-Link has since revoked the digital signatures on all files served before May 15, 2024. That means even if you have a legitimate old file, your router’s update mechanism will now reject it as invalid. tplink download center patched
In late October 2023, security researchers disclosed a critical vulnerability residing in the web application powering the TP-Link Download Center (https://www.tp-link.com/en/download-center.html). The vulnerability, tracked as CVE-2023-42555, allowed remote attackers to execute arbitrary code on the server. This report details the technical nature of the flaw, the potential impact on users, and the remediation steps taken by TP-Link. Even if the Download Center is now secure,
TP-Link has replaced vulnerable firmware files on the Download Center with patched versions for the following models (non-exhaustive): | Model | Previous Vulnerable Version | Patched Version | Release Date | |-------|----------------------------|----------------|----------------| | Archer AX6000 | 1.0.6 Build 20220901 | 1.0.8 Build 20231120 | 2024-01-15 | | Deco X60 | 1.2.1 Build 20220810 | 1.2.3 Build 20231005 | 2023-12-01 | | Tapo C200 | 1.0.14 | 1.0.18 | 2024-02-10 | Because those older files were never validated
Delete any old bookmarks pointing to tp-link.com/support/download. Use the official global entry point: https://www.tp-link.com/us/support/download/
The "tplink download center patched" saga has permanently changed the playing field. Moving forward, expect the following trends:
If you are looking for features not currently available in the stock firmware, consider these safer alternatives: