Notebookcheck Logo

TP-Link router from your provider: patching is not up to you

White Wi-Fi router with three antennas and a power supply on a yellow background
ⓘ Aditya Singh / Pexels
TP-Link lists five flaws in ISP-managed routers. One model on the list is rented out in Germany.
On 10 August TP-Link reported five vulnerabilities in routers that internet providers hand out to their customers. One model on the list is rented out in Germany. The worst flaw walks straight past the router password. You cannot repair it yourself, and there is no firmware to download. Whether your particular variant is affected is something the maker deliberately does not say.

There is a box in your hallway that you never bought. It belongs to your internet provider, you pay a few euros a month for it, and since the day it was installed you have probably not looked at it once.

On 10 August TP-Link published a list that this box might be on.

The advisory is titled "Multiple Vulnerabilities in ISP-Managed TP-Link Networking Products" and describes five weaknesses in devices that internet providers hand out to their customers. The table inside it lists 65 models. One of them is the VX800v(DE), and that model carries a cross in all five columns.

That is the exact device M-net rents to private customers in Munich, Augsburg and the Allgäu. Four euros a month, an all-in-one router for DSL and fiber.

What the flaw actually allows

The worst of the five is tracked as CVE-2025-30237, the unique number under which security flaws are listed worldwide. TP-Link describes it as broken access control in the web interface of the router. Certain requests never check whether whoever sent them is logged in.

Anyone who crafts the right request reaches functions that are meant to be reserved for the administrator. No valid credentials needed. The password you set during setup plays no part in it, because at that point nobody asks for it.

And now the limit, without which the rest of this would be scaremongering. The attacker has to be on the same network. This is not an attack that runs across the internet against every connection. It hits people who let guests onto the main Wi-Fi, who share an apartment or live in a building with one shared network, or who already have an infected device sitting inside. No public exploit code is known so far, and there are no documented attacks.

That does not make it harmless. It only moves the question. The question is not whether someone will attack you tomorrow. It is who closes the hole.

Table listing four device types, their series prefixes and example models
ⓘ Notebookcheck
The VX800v(DE) is affected by all five flaws. TP-Link repairs it with firmware 800.0.16.

You are not the one who fixes it

With a router from an electronics store the story would end here. Download the firmware, install it, done.

With a device from your provider it does not. TP-Link writes in the same advisory:

"For affected devices running ISP-managed firmware, remediation efforts will be coordinated through the respective Internet Service Providers."

And a few lines further down:

"Firmware images for affected ISP-specific variants may not be publicly available for direct download."

In plain terms, there is no file you could download. The provider decides when the update arrives, and it decides that for all of its customers at once. You notice once it has happened. Or you never notice at all.

That is the real point of this case. Not the flaw, the responsibility. The device sits in your home, it hangs off your line, every phone and every television in the household runs through it. And the only party that can change anything about it sits somewhere else.

For the VX800v, TP-Link names 800.0.16 as the repaired release. Whether it is already running on yours is written in your router's web interface.

Not even the question of whether it affects you

Two sentences in the footnotes of the table make the case more awkward still.

"Detailed SKU-level applicability varies per ISP deployment and is not publicly enumerated."

"Applicability is based on generic model analysis as ISP-specific variants may differ."

What TP-Link lists there are the general retail versions. Which build a given provider actually ships, how it was adapted and whether it carries the same weaknesses is nowhere public. And not by accident, but by stated policy.

So from your own living room you cannot settle even the simplest question. You read the model off the sticker, you find it on the list, and you still do not know whether your variant belongs to it. The only party that can tell you is the same one holding the update.

What you can still do

The sticker on the underside gives you the model. If the name starts with HB, HX, HC, EB, EC, EX, XC, XX or VX, the list is worth a look.

The firmware version sits in the router's web interface, usually under System Tools or Device Information. If it is older than the repaired release, ask your provider when the update is coming. That question is the only lever you have, and it works better when a lot of people ask it.

Until then, two things help right away. Switch off remote access and remote management as far as the interface lets you. And set up a guest network for visitors. Letting guests onto the main Wi-Fi removes exactly the condition that makes this attack hard.

The maker has a history

That it is TP-Link publishing this list is no chance find. The company has been under scrutiny for months.

The US cyber security agency CISA lists several TP-Link flaws in its catalog of vulnerabilities known to be exploited, the oldest of them from 2015. In February 2026 the attorney general of Texas sued the company, arguing that the routers had been advertised as secure while known firmware holes stayed open. In March the telecom regulator FCC banned sales of new routers built outside the United States.

There is one more thing about this particular device. The VX800v is not making its first appearance in a security advisory in 2026. February brought one of its own, with different numbers and a different firmware count. So the model keeps turning up.

You can read that in two directions, and both of them hold. A maker that reports a lot of flaws is either unusually sloppy or unusually open. What counts this week is the third observation. Even when it reports cleanly and repairs cleanly, the repair only reaches you if your provider passes it on.

Numbered list of five check steps from the label to the guest network
ⓘ Notebookcheck
Five steps that are still yours when the router belongs to your provider and not to you.

What is left

Germany has had router freedom since 2016. Nobody has to take the provider's device, anyone may connect their own. Whoever did that is not affected by this case and gets their updates straight from the maker.

Whoever kept the rented box, and that is most people, chose the convenience. It arrives preconfigured, it works right away, and when something breaks someone else is responsible. The price for that is written in this advisory. The same someone else is also responsible when a hole is standing open, and you learn neither whether you are affected nor when it will be closed.

In practice that means looking once at which device is standing in your home and which firmware it runs. Two minutes, once a year. And if the version is too old, ask. Not because someone will be on your network tomorrow, but because asking is the only lever this arrangement leaves you.

Source(s)

Google LogoAdd as a preferred source on Google
Mail Logo

No comments for this article

Got questions or something to add to our article? Even without registering you can post in the comments!
No comments for this article / reply

static version load dynamic
Loading Comments
> Expert Reviews and News on Laptops, Smartphones and Tech Innovations > Reviews > TP-Link router from your provider: patching is not up to you
Steffen Zahn, 2026-08-28 (Update: 2026-08-27)