Patch Your TP-Link Wi-Fi Range Extender Now

A flaw exists in four models of TP-Link Wi-Fi range extenders that could let an attacker take over the device through the internet and see everything you do online.

Credit: TP-Link

(Image credit: TP-Link)

The flaw was discovered in a TP-Link RE365 model, sold in Europe, by IBM X-Force researcher Grzegorz Wypych and disclosed today (June 18). In an official IBM blog post, Wypych said he had privately contacted TP-Link, which confirmed the flaw.

Wypych said the company told him the flaw also affected the RE650 model, sold in the United States, the United Kingdom and Canada, as well as two older models, the RE350, sold in all three countries, and the RE500, sold in the U.S. and Canada.

TP-Link has posted patches for all four models on its website. The patches must be downloaded and installed manually by the user, who must also make sure that he or she has the correct hardware version corresponding to the firmware, as well as the firmware corresponding to the user's country of residence.

Here are links to the U.S. firmware of the RE350, the RE500 and the RE650, the U.K. firmware of the RE350, the RE365 and the RE650, and the Canadian firmware of the RE350. Canadian firmware patches for this flaw do not yet appear to be available for the RE500 and the RE650.

For other countries or regions, change the "us", "uk" or "ca" in each URL to your country or region's internet country code, e.g. "eu", "pt" or "pl", or go to TP-Link's "Choose your location" page to be redirected to the front page of each regional TP-Link website.

The firmware to download and install will be dated to late May or early June with the note "Fixed CVE-2019-7406 discovered by IBM to increase security."

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Latest in Routers
The eero Pro 7 next to the eero Max 7 on a desk
Eero Pro 7 vs Eero Max 7: Which Wi-Fi 7-powered eero mesh system should you buy?
Eero Pro 7 sitting on counter
Eero Pro 7 review: Fast Wi-Fi 7 mesh speeds simplified
Netgear Orbi 873 on desk
Netgear Orbi 870 review: A great Wi-Fi 7 mesh kit for long range performance
TP-Link's Deco BE65-Outdoor Wi-Fi 7 mesh node mounted to a pole at CES 2025
TP-Link’s new outdoor mesh extender will give you true Wi-Fi 7 speeds right in your backyard
The MSI Roammii BE Lite dual-band mesh Wi-Fi 7 router on a table
Upgrading to Wi-Fi 7 is about to get more complicated — and these new routers are to blame
TP- Link Archer AX55 sitting on desk
This Chinese router company with 65% market share in the US could be banned — what you need to know
Latest in News
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
NYTimes Connections
NYT Connections today hints and answers — Monday, March 24 (#652)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #386 (Monday, March 24 2025)
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
  • DIY_Aaron_82
    I don't have that but, thanks for the info. Good job i say! Seriously, very cool u take the time to post that. Thank You.
    Reply