This top TP-Link router ships with some serious security flaws

TP-Link AC1200 Archer C50 (v6)
(Image credit: TP-Link)

Upgrading your wireless router with a new model from Amazon is certainly a good idea if you're working from home but new research from CyberNews has revealed that one of the most popular routers from TP-Link frequently featured on the ecommerce giant's store ships with vulnerable firmware.

Shenzhen-based TP-Link is the world's number one manufacturer of consumer WiFi networking products with yearly sales of 150m devices and a 42 percent share of the global consumer WLAN market. The company's routers are also often awarded “Amazon's Choice” badges in the “WiFi router” category on Amazon.

The TP-Link AC1200 Archer C50 (v6) is the best-selling “Amazon's Choice” Wi-Fi router in the UK and is mainly sold within the European market though another version is also available on Amazon's online store in the US. 

During its investigation into this router, CyberNews found numerous flaws within its default firmware as well as its web interface. For this reason, the news outlet recommends that all TP-Link AC1200 Archer C50 (v6) owners upgrade their devices to the latest firmware as soon as possible.

Known flaws in default firmware

According to CyberNews, the TP-Link AC1200 Archer C50 (v6) ships with outdated firmware that is vulnerable to dozens of known security flaws. WPS is also enabled by default on the device which could allow an attacker to brute-force the router while its admin credentials and configuration backup files are encrypted using weak protocols that could easily be broken.

At the same time, the default version of the router's web interface app suffers from multiple bad security practices and vulnerabilities including clickjacking, charset mismatch, cookie slack, private IP disclosures, weak HTTPS encryption and more. 

Thankfully most of these flaws have now been patched but CyberNews points out that some were only patched halfway through. For instance, the backend of the router still seems to be secured in such a way that an attacker could potentially find an entry point within the web interface and re-exploit previously known flaws.

CyberNews reached out to TP-Link to inform the company of its discoveries and it said that it will force firmware updates on the affected devices while owners will receive “relevant notifications” about these updates via their management interface.

The lesson here is that while you may have purchased a brand new device from Amazon or any other online or offline retailer for that matter, you still need to take the time and ensure that your router is updated to the latest firmware to protect your network and your data.

Via CyberNews

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
A hacker wearing a hoodie sitting at a computer, his face hidden.
I just learned something awful about my home Wi-Fi setup thanks to iFixit’s ‘worst of CES 2025’ awards
China
US government mulls entire TP-Link product ban - routers, switches and more all set to be blocked
cables going into the back of a broadband router on white background
Netgear urges users to patch major router security issues now
Security
Zyxel says it won’t patch security flaws in its old routers
One of the best wifi router picks against a techradar background
The best WiFi routers in 2025: our top picks for wireless connectivity
Extendable WiFi 7 KV
Don't buy a router, buy a fast and secure ASUS WiFi 7 extendable router
Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day