← Routers
F

TP-Link WiFi 6 Router

Silently collects MAC addresses of every device in your home. 18 critical CVEs.
Fail
TP-Link · 🇨🇳 China · Cellular
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
FCC ID: TE7AX73
Chipset: Broadcom BCM6750 tri-core 1.5GHz
App: com.tplink.tether
Manufacturer: TP-Link
Model: Archer AX73 AX5400

⚠️ The bottom line

TP-Link says they collect data when you use their services. But the router secretly sends your network information to a third-party company (Avira) every single minute, even when you have turned off the security feature that supposedly needs that data. You cannot stop it without breaking your router. TP-Link sells a "security" feature called HomeCare that scans ALL internet traffic from every device in your home. But multiple US government agencies are investigating whether TP-Link could be forced by Chinese law to hand over exactly this kind of data to the Chinese government. Your router's "security" feature is also a surveillance capability — and the US government considers this a national security threat.

Legal jurisdiction
🇨🇳 China (headquarters)
National Intelligence Law read more →
Company must secretly hand data to Chinese intelligence on request
Data Security Law read more →
State can classify any data as 'important' and demand access for national security
Spying
4/4 EXTREME
Is someone spying on me?
Data Sharing
4/4 EXTREME
Who gets my data?
Kids at risk
Security
4/4 EXTREME
Is it actually secure?
Kids at risk
Honesty
4/4 EXTREME
Can I trust what they say?
Kids at risk
REPLACE Extreme risk. Look for alternatives or lock down hard.
10Contradictions
4Critical
6High
0Medium
7Sources
Findings by concern
Spying 4/4 EXTREME 3 findings
⚠️ criticalpolicy claims vs firmware analysis
TP-Link says they collect data when you use their services. But the router secretly sends your network information to a third-party company (Avira) every single minute, even when you have turned off the security feature that supposedly needs that data. You cannot stop it without breaking your router.

What they claim: TP-Link privacy policy states they collect data when users "access or use" their services, implying active user engagement triggers collection.

What we found: Avira SafeThings SDK embedded in router firmware sends traffic metadata to Avira cloud servers (safethings.avira.com, iot-api.avira.com) every minute — over 80,000 requests per 24 hours — regardless of whether the HomeCare/HomeShield security feature is enabled or disabled. Users cannot opt out without causing router instability.

⚠️ criticalfirmware analysis vs regulatory findings
TP-Link sells a "security" feature called HomeCare that scans ALL internet traffic from every device in your home. But multiple US government agencies are investigating whether TP-Link could be forced by Chinese law to hand over exactly this kind of data to the Chinese government. Your router's "security" feature is also a surveillance capability — and the US government considers this a national security threat.

What they claim: TP-Link markets HomeCare as a security feature that protects your home network using Trend Micro threat intelligence.

What we found: HomeCare performs deep packet inspection (DPI) of ALL traffic from every device in your home. The router occupies a privileged position seeing every website visit, every smart device communication, and every file transfer. Meanwhile, the US House Select Committee on the CCP, Commerce Department, Justice Department, and Defense Department are all investigating TP-Link over concerns that China's National Intelligence Law (2017) could compel TP-Link to share this data with the Chinese government. Microsoft confirmed a botnet of compromised TP-Link routers (CovertNetwork-1658) was used by Chinese state actor Storm-0940.

⚡ highapp permissions vs firmware analysis
The TP-Link Tether app asks for permission to access your location, read your files, and draw over other apps — far more than what's needed to manage a router. Combined with the router itself sending data to 9 different cloud servers across three continents, you are being tracked from two directions: through your phone app AND through your router.

What they claim: Tether app requests CAMERA permission for QR code scanning during router setup.

What we found: While CAMERA access is justified for setup QR scanning, the app also requests ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, SYSTEM_ALERT_WINDOW (draw over other apps), READ_EXTERNAL_STORAGE, and WRITE_EXTERNAL_STORAGE. Combined with the router's ability to see all network traffic and firmware that phones home to 9 different cloud endpoints (including TP-Link cloud servers in US, EU, and Asia-Pacific regions), the app serves as a secondary data collection vector alongside the router itself.

Data Sharing 4/4 EXTREME 3 findings
⚡ highpolicy claims vs app permissions
TP-Link carefully words their privacy policy to say they do not use your personal info for targeted ads. But they never actually promise not to sell your data. Their app includes analytics trackers that monitor your behavior. The specific wording is a common legal technique that sounds protective but actually permits selling your data to other companies.

What they claim: TP-Link privacy policy states they "do not use information that personally identifies you to display interest-based ads."

What we found: The TP-Link Tether companion app (com.tplink.tether v4.12.212) includes Google Firebase Analytics tracker which collects user behavior data, and requests BILLING permission for in-app purchases. The policy carefully avoids stating they do not sell personal data — only that they do not use it for interest-based ads, leaving the door open for other forms of data monetization.

⚡ highpolicy claims vs firmware analysis
TP-Link's privacy policy vaguely mentions sharing data with "partners" without naming them. In reality, your router sends your network data to at least two other companies — Avira and Trend Micro — that most users have never heard of and certainly didn't agree to share data with. You bought a TP-Link router, but your data goes to multiple companies you never chose.

What they claim: TP-Link privacy policy describes sharing data with "authorized partners" and "service providers" without specific naming.

What we found: Firmware analysis reveals the router connects to at least 2 third-party data processors not prominently disclosed: Avira SafeThings (safethings.avira.com, iot-api.avira.com) for traffic analysis and Trend Micro for HomeCare deep packet inspection. These third parties receive detailed information about network traffic patterns from every device in the home. The policy's vague "authorized partners" language obscures that your network traffic data flows to multiple Chinese-headquartered (TP-Link) and European (Avira/Gen Digital) companies.

⚡ highapp permissions vs regulatory findings
To use your router remotely, you must create a TP-Link Cloud account with your name, address, phone number, and email. TP-Link is a Chinese company legally required to cooperate with Chinese intelligence agencies if asked. Three US government departments are investigating exactly this risk. Your personal details are stored by a company that Chinese law says must hand over data if the government demands it.

What they claim: Tether app requires TP-Link Cloud account for remote management, collecting name, address, phone, email.

What we found: TP-Link is headquartered in Shenzhen, China, and is subject to China's National Intelligence Law (2017) Article 7: "All organizations and citizens shall support, assist, and cooperate with national intelligence efforts." User account data (name, address, phone, email) collected by the Tether app flows to TP-Link cloud infrastructure. The US Commerce, Justice, and Defense departments are investigating whether this data could be compelled for disclosure to Chinese intelligence agencies.

Security 4/4 EXTREME 3 findings
⚠️ criticalfirmware analysis vs regulatory findings
Your TP-Link router automatically downloads and installs software updates from TP-Link's servers. Security researchers found that TP-Link's firmware update process has weak verification — it can be tricked into installing fake updates. The US government is investigating whether China could order TP-Link to push a malicious update to millions of routers. This means a single bad update could compromise every device in your home.

What they claim: TP-Link router firmware receives OTA updates automatically from TP-Link servers (download.tp-link.com, static.tp-link.com).

What we found: CVE-2024-54126 demonstrates improper signature verification in TP-Link Archer firmware upgrade process, allowing attackers to upload malicious firmware. Combined with the US government investigation into whether TP-Link could be compelled by Chinese law to push malicious updates, the automatic firmware update mechanism represents a potential supply chain attack vector. TP-Link controls what software runs on a device that sees all home network traffic.

⚠️ criticalregulatory findings vs firmware analysis
Microsoft caught Chinese government hackers using a network of hacked TP-Link routers to attack US government agencies and defense companies. This wasn't theoretical — it actually happened. The same type of security holes found in this router model (Archer AX5400) were used to take over thousands of TP-Link routers and turn them into weapons for cyber espionage. Your home router could be part of a foreign intelligence operation without you knowing.

What they claim: Microsoft documented that compromised TP-Link routers formed the CovertNetwork-1658 botnet used by Chinese state-sponsored hackers (Storm-0940).

What we found: The router firmware has 3 critical CVEs (CVE-2024-21833, CVE-2023-1389, CVE-2024-5035) demonstrating persistent command injection vulnerabilities across the Archer product line. The botnet maintained ~8,000 active compromised devices at any time, with 20% being TP-Link routers. These compromised routers were used for password spray attacks against North American and European think tanks, government organizations, NGOs, and defense industry targets.

⚡ highfirmware analysis vs app permissions
TP-Link markets this router with security features like HomeCare and parental controls. But the router's own software has a history of critical security holes that let attackers take it over remotely. One vulnerability (CVE-2024-21833) specifically affects this model and lets anyone on your network run any command on the router. The company that wants to protect your network can't protect its own router.

What they claim: Router firmware has 4 known critical/high CVEs in the Archer product line, including CVE-2024-21833 (CVSS 8.8) affecting the AX5400 specifically.

What we found: Despite this pattern of critical security vulnerabilities (3 critical, 1 high severity) across the Archer firmware family, the Tether app (v4.12.212) includes only 2 trackers — Google CrashLytics and Firebase Analytics — and no security-focused telemetry for detecting compromised routers. TP-Link marketing emphasizes security features (HomeCare, parental controls) while the underlying firmware has a documented history of remotely exploitable command injection vulnerabilities.

Honesty 4/4 EXTREME 1 finding
⚡ highpolicy claims vs regulatory findings
TP-Link promises that parental controls browser history stays on your router and is never uploaded. But they also say their security features record and analyze every website every device tries to visit — and THAT data goes to the cloud. It's the same information (what websites you visit) being treated differently based on which feature label they put on it. Your browsing is monitored either way.

What they claim: TP-Link Tether privacy policy states parental controls data (browser history) is "only stored on the TP-Link product" and "won't be uploaded or stored on TP-Link cloud servers."

What we found: When Real-Time Protection is enabled, TP-Link "records and analyzes a device's attempted URL connections" — URL data IS processed. The router contacts TP-Link cloud servers (use1-api.tplinkcloud.com, euw1-api.tplinkcloud.com, aps1-api.tplinkcloud.com) and Avira SafeThings servers constantly. The distinction between "parental controls data stays local" and "security feature data goes to cloud" is a technicality — both involve monitoring what websites every device in your home visits.

What happened to real people
Documented incidents involving TP-Link products and user data.
TP-Link routers used as infrastructure in Volt Typhoon — Chinese state-sponsored attacks targeting US critical infrastructure including water, energy, and communications. CISA advisory. [source]
What your data is worth to governments
Jurisdiction: CN (China National Intelligence Law (Article 7: all organisations must support national intelligence work)).
Documented: TP-Link routers used as infrastructure in Volt Typhoon — Chinese state-sponsored attacks targeting US critical infrastructure including water, energy, and communications. CISA advisory.
China National Intelligence Law
Sources