For those who are using supported/unsupported TP-link routers

During my weekly check of my home network, BLINDSIDED, I found two WiFi MAC addresses that I couldn’t address or find what they were connected to. The first was listed as “none-243”, upon disabling it my Alexa 25" smart display went offline. Evidently, it slipped an AI update into its firmware without any notice. Google has quietly confirmed that for me via their support. I have since determined it safe and renamed the device as it should be. No there there for that one. Attention focus here is, AI IS being pushed without the consent nor notification to the users of Alexa devices. USE CAUTION and audit frequently.

The second one, is the reason for this post. It is a stern warning to TP-Link device owners, even if your router is current with its firmware and no identified CVE’s are outstanding and unpatched. I found the following MAC address listed with an IP address that was NOT listed in my routing tables, not logged in the router. Below is where that was ultimately traced:

MAC address: 18-EF-3A-C8-85-53

You can decode a MAC address using this free service online: Here are my results.
Note: These devices are manufactured in China and have been the subject of national security issue over the past 2-3 years here in the USA.
https://dnschecker.org/mac-lookup.php?query=18-EF-3A-C8-85-53

*** What I know: This router, a BE550 is currently supported and its firmware IS the most recent available. There are NO settings enabled in the router that would indicate the use of AI, no VPN, no QOS enabled, no offered security side software enabled. I have this MAC address blocked at the router level, to date it has NOT reappeared. I have reset this router and conducted a 32 character password for the admin login and each network that is active.

AI has this info on the topic:

AI Overview

The TP-Link Archer BE550 does not currently have any published, unpatched critical Remote Code Execution (RCE) or zero-day vulnerabilities in its active lifecycle. However, it is important to be aware of certain outstanding security issues and industry controversies related to the brand: [1, 2]

Key Security & Brand Factors to Consider

  • Third-Party Credential Warnings: TP-Link recently sent account security notifications alerting users if their TP-Link ID credentials were found in third-party data breaches. While your router itself isn’t hacked, this triggers password resets to prevent account takeovers. [1]
  • Industry and Government Scrutiny: The U.S. government has raised ongoing supply-chain and espionage concerns regarding Chinese-manufactured networking equipment, leading to broader FCC regulations on foreign-produced consumer routers. [1, 2]
  • Legacy Device Vulnerabilities: While the BE550 is a newer Wi-Fi 7 model, TP-Link has had high-severity flaws in its legacy/End-of-Life (EOL) lineups (e.g., CVE-2023-50224) that have been actively targeted by state-sponsored threat actors. [1, 2]

General Router Security Best Practices

To keep your network safe from known exploit vectors (like DNS manipulation and credential stuffing), ensure you are actively managing your device: [1]

1. Update Firmware: Ensure your router is continuously on the latest firmware. You can check for and apply updates via the web management portal or by using the official TP-Link Tether App. [1]
2. Upgrade Credentials: Never use the default admin username and password. Create a strong, unique Wi-Fi password and administrative login.
3. Enable Two-Step Verification (2FA): Turn on 2FA in the Tether app for your TP-Link ID to prevent unauthorized remote access to your network settings.
4. Disable Remote Management: Unless you explicitly need to access your home network from outside, disable remote management in the router’s settings. [1]

Be diligent and audit your devices if you own ANY TP-Link device.

Regards,
SA

1 Like

Hi SoulAsylum:

That’s a good catch, but do you mean you recently blocked the MAC address 18-EF-3A-C8-85-53 (Sichuan AI-Link Technology, China)? I’m just wondering if this could prevent future firmware / security updates from being delivered to your TP-Link Archer BE550 router.

Sorry for the tardy reply. YES Maam. I indeed have blocked that MAC address on the router. It has attempted to reappear once but gets auto-blocked. I can indeed check for firmware updates as normal with this blocked. Conversely, I have filed a complaint with CISA giving them the information posted above for review.

Edited: I had looked deeper earlier and lost the AI material I found. Here is what AI has to tell us

AI Overview

Sichuan AI-Link Technology is a massive manufacturer of Wi-Fi and Bluetooth chips used inside everyday smart home devices. If this name appears on your router’s device list, it is almost certainly a harmless gadget in your home, not a hacker. [1, 2, 3]

Common Devices from AI-Link:

  • Robot vacuums
  • Smart plugs, lights, and switches
  • Air conditioners, humidifiers, and air purifiers
  • Smart TVs, media boxes, and streaming sticks
  • Smart scales and medical instruments [1, 2, 3, 4]

How to find out exactly what it is:

  1. Change your Wi-Fi password in your router’s admin panel (learn how using tools like Fing’s Wi-Fi Guide).
  2. Restart your router.
  3. Reconnect your known devices one by one.
  4. The unidentified AI-Link device will remain disconnected, prompting you to see which smart appliance in your home is no longer responding

Regards,
SA

1 Like