TP-Link router from your provider: patching is not up to you

There is a box in your hallway that you never bought. It belongs to your internet provider, you pay a few euros a month for it, and since the day it was installed you have probably not looked at it once.
On 10 August TP-Link published a list that this box might be on.
The advisory is titled "Multiple Vulnerabilities in ISP-Managed TP-Link Networking Products" and describes five weaknesses in devices that internet providers hand out to their customers. The table inside it lists 65 models. One of them is the VX800v(DE), and that model carries a cross in all five columns.
That is the exact device M-net rents to private customers in Munich, Augsburg and the Allgäu. Four euros a month, an all-in-one router for DSL and fiber.
What the flaw actually allows
The worst of the five is tracked as CVE-2025-30237, the unique number under which security flaws are listed worldwide. TP-Link describes it as broken access control in the web interface of the router. Certain requests never check whether whoever sent them is logged in.
Anyone who crafts the right request reaches functions that are meant to be reserved for the administrator. No valid credentials needed. The password you set during setup plays no part in it, because at that point nobody asks for it.
And now the limit, without which the rest of this would be scaremongering. The attacker has to be on the same network. This is not an attack that runs across the internet against every connection. It hits people who let guests onto the main Wi-Fi, who share an apartment or live in a building with one shared network, or who already have an infected device sitting inside. No public exploit code is known so far, and there are no documented attacks.
That does not make it harmless. It only moves the question. The question is not whether someone will attack you tomorrow. It is who closes the hole.

You are not the one who fixes it
With a router from an electronics store the story would end here. Download the firmware, install it, done.
With a device from your provider it does not. TP-Link writes in the same advisory:
"For affected devices running ISP-managed firmware, remediation efforts will be coordinated through the respective Internet Service Providers."
And a few lines further down:
"Firmware images for affected ISP-specific variants may not be publicly available for direct download."
In plain terms, there is no file you could download. The provider decides when the update arrives, and it decides that for all of its customers at once. You notice once it has happened. Or you never notice at all.
That is the real point of this case. Not the flaw, the responsibility. The device sits in your home, it hangs off your line, every phone and every television in the household runs through it. And the only party that can change anything about it sits somewhere else.
For the VX800v, TP-Link names 800.0.16 as the repaired release. Whether it is already running on yours is written in your router's web interface.
Not even the question of whether it affects you
Two sentences in the footnotes of the table make the case more awkward still.
"Detailed SKU-level applicability varies per ISP deployment and is not publicly enumerated."
"Applicability is based on generic model analysis as ISP-specific variants may differ."
What TP-Link lists there are the general retail versions. Which build a given provider actually ships, how it was adapted and whether it carries the same weaknesses is nowhere public. And not by accident, but by stated policy.
So from your own living room you cannot settle even the simplest question. You read the model off the sticker, you find it on the list, and you still do not know whether your variant belongs to it. The only party that can tell you is the same one holding the update.
What you can still do
The sticker on the underside gives you the model. If the name starts with HB, HX, HC, EB, EC, EX, XC, XX or VX, the list is worth a look.
The firmware version sits in the router's web interface, usually under System Tools or Device Information. If it is older than the repaired release, ask your provider when the update is coming. That question is the only lever you have, and it works better when a lot of people ask it.
Until then, two things help right away. Switch off remote access and remote management as far as the interface lets you. And set up a guest network for visitors. Letting guests onto the main Wi-Fi removes exactly the condition that makes this attack hard.
The maker has a history
That it is TP-Link publishing this list is no chance find. The company has been under scrutiny for months.
The US cyber security agency CISA lists several TP-Link flaws in its catalog of vulnerabilities known to be exploited, the oldest of them from 2015. In February 2026 the attorney general of Texas sued the company, arguing that the routers had been advertised as secure while known firmware holes stayed open. In March the telecom regulator FCC banned sales of new routers built outside the United States.
There is one more thing about this particular device. The VX800v is not making its first appearance in a security advisory in 2026. February brought one of its own, with different numbers and a different firmware count. So the model keeps turning up.
You can read that in two directions, and both of them hold. A maker that reports a lot of flaws is either unusually sloppy or unusually open. What counts this week is the third observation. Even when it reports cleanly and repairs cleanly, the repair only reaches you if your provider passes it on.

What is left
Germany has had router freedom since 2016. Nobody has to take the provider's device, anyone may connect their own. Whoever did that is not affected by this case and gets their updates straight from the maker.
Whoever kept the rented box, and that is most people, chose the convenience. It arrives preconfigured, it works right away, and when something breaks someone else is responsible. The price for that is written in this advisory. The same someone else is also responsible when a hole is standing open, and you learn neither whether you are affected nor when it will be closed.
In practice that means looking once at which device is standing in your home and which firmware it runs. Two minutes, once a year. And if the version is too old, ask. Not because someone will be on your network tomorrow, but because asking is the only lever this arrangement leaves you.
Source(s)
TP-Link security advisory on ISP-managed devices (CVE-2025-30237 to CVE-2025-30241, as of 10 August 2026) · M-net on the TP-Link VX800v · Cyber Security News on the five flaws (14 August 2026) · BleepingComputer on the wider picture at TP-Link (25 March 2026)





