During my weekly check of my home network, BLINDSIDED, I found two WiFi MAC addresses that I couldn’t address or find what they were connected to. The first was listed as “none-243”, upon disabling it my Alexa 25" smart display went offline. Evidently, it slipped an AI update into its firmware without any notice. Google has quietly confirmed that for me via their support. I have since determined it safe and renamed the device as it should be. No there there for that one. Attention focus here is, AI IS being pushed without the consent nor notification to the users of Alexa devices. USE CAUTION and audit frequently.
The second one, is the reason for this post. It is a stern warning to TP-Link device owners, even if your router is current with its firmware and no identified CVE’s are outstanding and unpatched. I found the following MAC address listed with an IP address that was NOT listed in my routing tables, not logged in the router. Below is where that was ultimately traced:
MAC address: 18-EF-3A-C8-85-53
You can decode a MAC address using this free service online: Here are my results.
Note: These devices are manufactured in China and have been the subject of national security issue over the past 2-3 years here in the USA.
https://dnschecker.org/mac-lookup.php?query=18-EF-3A-C8-85-53
*** What I know: This router, a BE550 is currently supported and its firmware IS the most recent available. There are NO settings enabled in the router that would indicate the use of AI, no VPN, no QOS enabled, no offered security side software enabled. I have this MAC address blocked at the router level, to date it has NOT reappeared. I have reset this router and conducted a 32 character password for the admin login and each network that is active.
AI has this info on the topic:
AI Overview
The TP-Link Archer BE550 does not currently have any published, unpatched critical Remote Code Execution (RCE) or zero-day vulnerabilities in its active lifecycle. However, it is important to be aware of certain outstanding security issues and industry controversies related to the brand: [1, 2]
Key Security & Brand Factors to Consider
- Third-Party Credential Warnings: TP-Link recently sent account security notifications alerting users if their TP-Link ID credentials were found in third-party data breaches. While your router itself isn’t hacked, this triggers password resets to prevent account takeovers. [1]
- Industry and Government Scrutiny: The U.S. government has raised ongoing supply-chain and espionage concerns regarding Chinese-manufactured networking equipment, leading to broader FCC regulations on foreign-produced consumer routers. [1, 2]
- Legacy Device Vulnerabilities: While the BE550 is a newer Wi-Fi 7 model, TP-Link has had high-severity flaws in its legacy/End-of-Life (EOL) lineups (e.g., CVE-2023-50224) that have been actively targeted by state-sponsored threat actors. [1, 2]
General Router Security Best Practices
To keep your network safe from known exploit vectors (like DNS manipulation and credential stuffing), ensure you are actively managing your device: [1]
1. Update Firmware: Ensure your router is continuously on the latest firmware. You can check for and apply updates via the web management portal or by using the official TP-Link Tether App. [1]
2. Upgrade Credentials: Never use the default admin username and password. Create a strong, unique Wi-Fi password and administrative login.
3. Enable Two-Step Verification (2FA): Turn on 2FA in the Tether app for your TP-Link ID to prevent unauthorized remote access to your network settings.
4. Disable Remote Management: Unless you explicitly need to access your home network from outside, disable remote management in the router’s settings. [1]
Be diligent and audit your devices if you own ANY TP-Link device.
Regards,
SA
