We've seen some serious cases of negligence from certain companies, but what just happened with TP-Link makes us want to put a paper bag over our heads in embarrassment. The Chinese manufacturer let the domains lapse for two of the addresses that its pre-2014 products use as their initial configuration portal, and the new owners are asking 2.5 million dollars... for just one of them.
The Configuration Portal Approach
For a long time, leading manufacturers of modems, routers, switches, WiFi extenders and other similar devices have looked for ways to simplify the configuration process. I'm the first to admit that configuring a router is anything but intuitive, but once you've crossed swords with several models, the general parameters are easy to follow. However, I understand that users feel uncomfortable typing 192.168.1.1 where a web address usually goes, and in an attempt to leverage that "intuition", so to speak, several companies decided to implement partial or full addresses as configuration portals. For example, Belkin uses http://router, which works quite well, while Asus offers http://router.asus.com. On first setup, these addresses correctly send the user to the configuration page, but once the internet connection is active, those addresses could be resolved.
The Domain Lapse
This last detail demands some responsibility from the manufacturer, and from what we've been able to verify, the folks at TP-Link left it at the door. According to Amitay Dan of security firm Cybermoon, TP-Link forgot to renew the registrations for two of its domains, tplinklogin-dot-net and tplinkextender-dot-net. These addresses appear on the labels of its products sold before 2014, and now they show others (tplinkwifi-dot-net and tplinkrepeater-dot-net to be more precise), but that's not the point. By forgetting the renewal, both domains came under the control of external parties, who quickly put them up for sale. How much are they asking? Tplinklogin-dot-net is the more popular of the two, with 4.4 million monthly visits, and the magic number is 2.5 million dollars.
The Security Risk
Faced with such a price, TP-Link's decision was nothing other than to abandon the domains completely and modify all references to them on its official page, but that doesn't eliminate the security risk. Both domains could turn into a phishing attack (by posing as an official page) or a malware distribution mechanism, handing out fake "firmware updates". Fortunately, protecting yourself is simple: We must ignore both domains and use the device's internal IP address to carry out its configuration (be it 192.168.0.1, 192.168.1.1, 10.0.0.1, or another variant). What will happen to them? Due to the problem they represent, they will likely be blocked at browser or ISP level. Until then, owners of TP-Link hardware with a few years on it might want to tread a little more carefully.