XE75 security Issues

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

XE75 security Issues

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
XE75 security Issues
XE75 security Issues
2024-04-12 06:54:30
Model: Deco XE75  
Hardware Version: V2
Firmware Version: 1.2.5

Why can guests in the guest WiFi access the local registration page (192.168.x.x) of the Deco and log in?

This is a flawed network design.

 

Please clarify!!!


Why can devices access the main WiFi from the IOT WiFi by default? You have to manually mark it as an isolated device. This should be the other way around. Isolated by default and grant access to the main WiFi if necessary.
This is flawed and poor network design and has nothing to do with network security.

If someone breaks into the IOT network with WPA encryption, they automatically have access to devices on the main network with WPA3 encryption.
This is madness.

 

Please clarify!!!

 

At this point I regret buying a Tp Link Deco.

  2      
  2      
#1
Options
4 Reply
Re:XE75 security Issues
2024-04-13 11:55:19

@Chris78 First of all, even if they access the page, they can't log in without the password of TP-Link owner ID (which I'm assuming is you).

 

Second, If the XE75 are running in router mode, the main network & guest network are supposed to be isolated.

 

If they're running in access point mode, then go to Deco app> "More" tab> Guest Network> Advanced & disable "allow local access".

Just a M4 (2-pack) user who regrets buying it
  0  
  0  
#2
Options
Re:XE75 security Issues
2024-04-13 12:00:38 - last edited 2024-04-13 12:02:05

  @ImtiazAli 

 

Please read my post. I don't speak about guest network and main network. 

I speak about IOT network and Main network.

So if you can read and understand than you can post an useful reply. 

Further i don't use AP mode. This is for the router Mode. 

  0  
  0  
#3
Options
Re:XE75 security Issues
2024-04-13 12:14:09

Chris78 wrote

Why can guests in the guest WiFi access the local registration page (192.168.x.x) of the Deco and log in?

  @Chris78 This is the first line of your post... can you read what you said???

Just a M4 (2-pack) user who regrets buying it
  0  
  0  
#4
Options
Re:XE75 security Issues
2024-04-15 12:09:27

  @Chris78 

Hi, you did mention the Guest access with the Main network in your first post.

Did Deco XE75 work in wireless router mode?

If yes, It is expected on Deco that the guest devices could still access the network gateway/192.168.68.1 which is the default LAN of Deco since the guest devices also need internet access.

 

As for the IOT network, It is not isolated from the main network by default. It is more like an extra 2.4G SSID for smart home devices.

Some users have the central IOT hub wired connected to Deco or 5GHz of the main network for better bandwidth and still hope to communicate with smart devices on the IOT network so we don't make the IOT network isolated by design, then add "Device Isolation" instead for users who worried about the potential risk of smart home security.

 

Your concern regarding the potential risk of non-isolation between the IoT network and the main network is completely valid. I would love to report the feature request to the engineers. I also hope you can have faith in the Deco network security. It has built-in firewall settings and the HomeSheild Security kit. As a trusted leader in network equipment manufacturing, I am confident that our engineers will prioritize creating a secure network environment for our users.

 

 

PS: I have removed your last reply. I truly completely that user can be quite frustrated when their Deco is not working as expected. But I wish the discussion remains polite and friendly. Many users answer the questions and share their own experiences with Deco voluntarily. I hope they can also receive some respect and appreciation.

 

Thank you very much and best regards.

 

 

  0  
  0  
#6
Options