• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

TP-Link Said to be Sharing all Router Traffic with Third Party

TheLostSwede

News Editor
Joined
Nov 11, 2004
Messages
17,495 (2.40/day)
Location
Sweden
System Name Overlord Mk MLI
Processor AMD Ryzen 7 7800X3D
Motherboard Gigabyte X670E Aorus Master
Cooling Noctua NH-D15 SE with offsets
Memory 32GB Team T-Create Expert DDR5 6000 MHz @ CL30-34-34-68
Video Card(s) Gainward GeForce RTX 4080 Phantom GS
Storage 1TB Solidigm P44 Pro, 2 TB Corsair MP600 Pro, 2TB Kingston KC3000
Display(s) Acer XV272K LVbmiipruzx 4K@160Hz
Case Fractal Design Torrent Compact
Audio Device(s) Corsair Virtuoso SE
Power Supply be quiet! Pure Power 12 M 850 W
Mouse Logitech G502 Lightspeed
Keyboard Corsair K70 Max
Software Windows 10 Pro
Benchmark Scores https://valid.x86.fr/yfsd9w
These days, routers are quite complex devices that are doing much more than just routing data and are often the main security device on a home network. As such, we've seen a surge in third party services such as Asus' AIProtection that runs software from Trend Micro and Netgear Armor in cooperation with Bitdefender. Chinese TP-Link is likewise offering similar services, some in partnership with Trend Micro and some with Avira. It now appears that TP-Link's HomeCare service—that the company is offering in partnership with Avira—is sending data to Avira even when disabled in the UI, based on a thread over at Reddit.

The standard Avira features are meant to offer protection against malicious content, network intrusions and even against infected devices on the network that are said to be quarantined from other devices on the network. It also incorporates some basic parental control features, such as automatic content filtering and time controls. However, in this case, the issue isn't the functionality itself, but the fact that there apparently is no way to turn off the HomeCare feature, since even when seemingly disabled in the UI of the affected routers, it sends data to Avira. It seems to be a fairly large amount of data being sent as well, with the initial poster claiming over 80,000 requests in a 24 hour period. According to a review of a TP-Link product over on XDA-Developers from May last year, TP-Link said that they were working on a firmware update that would allow the Avira service to be turned off permanently.




However, it seems like no such option has materialized in close to a year since that comment from TP-Link and although it seems the data that is being sent is intended for Avira to use to improve their services, it also seems to go against the European GDPR rules to send user data to a third party, especially without the users consent. Back to Reddit, the poster contacted TP-Link, who claimed that the data sent was to check if the owner of the router had an active service with Avira or not, but this sounds rather preposterous considering that it wouldn't require 80,000 requests per day. To put it in a different context, that's close to once a second.

Multiple people on Reddit have chimed in saying that they're seeing exactly the same thing. Trying to block the requests isn't an option either, as this causes the routers in question to get stuck in a retry loop, which in turn leads to CPU usage spikes and causes issues with the general usage of the routers in question. Other users tried signing up for the trial of the paid-for service, but didn't see any changes in behavior, regardless if the service was enabled or disabled. The only slightly positive note on all of this is that Avira is a German company and could potentially be forced to amend how its service works based on the European GDPR regulation. However, it would still be up to TP-Link to issue a firmware release to the 13 or so routers that run the Avira service. Most of the routers are recent 802.11ax/WiFi 6 models and about half are part of TP-Link's Deco series of mesh systems.

View at TechPowerUp Main Site | Source
 

TheLostSwede

News Editor
Joined
Nov 11, 2004
Messages
17,495 (2.40/day)
Location
Sweden
System Name Overlord Mk MLI
Processor AMD Ryzen 7 7800X3D
Motherboard Gigabyte X670E Aorus Master
Cooling Noctua NH-D15 SE with offsets
Memory 32GB Team T-Create Expert DDR5 6000 MHz @ CL30-34-34-68
Video Card(s) Gainward GeForce RTX 4080 Phantom GS
Storage 1TB Solidigm P44 Pro, 2 TB Corsair MP600 Pro, 2TB Kingston KC3000
Display(s) Acer XV272K LVbmiipruzx 4K@160Hz
Case Fractal Design Torrent Compact
Audio Device(s) Corsair Virtuoso SE
Power Supply be quiet! Pure Power 12 M 850 W
Mouse Logitech G502 Lightspeed
Keyboard Corsair K70 Max
Software Windows 10 Pro
Benchmark Scores https://valid.x86.fr/yfsd9w
Yeah, and I'm the crazy one buying expensive gear from reputable vendors...
In fairness to TP-Link, their hardware isn't all that different from their competitors.
However, I would never, as I've said before here, use one of their devices with the default software on it, as a router facing the internet.
I put OpenWRT on both of my TP-Link devices and both of them are working better with OpenWRT than they did with the TP-Link firmware.
 
Joined
Feb 18, 2005
Messages
5,757 (0.80/day)
Location
Ikenai borderline!
System Name Firelance.
Processor Threadripper 3960X
Motherboard ROG Strix TRX40-E Gaming
Cooling IceGem 360 + 6x Arctic Cooling P12
Memory 8x 16GB Patriot Viper DDR4-3200 CL16
Video Card(s) MSI GeForce RTX 4060 Ti Ventus 2X OC
Storage 2TB WD SN850X (boot), 4TB Crucial P3 (data)
Display(s) 3x AOC Q32E2N (32" 2560x1440 75Hz)
Case Enthoo Pro II Server Edition (Closed Panel) + 6 fans
Power Supply Fractal Design Ion+ 2 Platinum 760W
Mouse Logitech G602
Keyboard Razer Pro Type Ultra
Software Windows 10 Professional x64
It now appears that TP-Link's HomeCare service that the company is offering in partnership with Avira, is sending data to Avira, if when disabled, based on a thread over at Reddit.

@TheLostSwede this sentence makes no grammatical sense.
 
Joined
Aug 12, 2020
Messages
1,207 (0.78/day)
I remember the time when Avira was actually good and go to antivirus package. It was is Win9x days though...
 
Joined
Mar 20, 2019
Messages
556 (0.27/day)
Processor 9600k
Motherboard MSI Z390I Gaming EDGE AC
Cooling Scythe Mugen 5
Memory 32GB of G.Skill Ripjaws V 3600MHz CL16
Video Card(s) MSI 3080 Ventus OC
Storage 2x Intel 660p 1TB
Display(s) Acer CG437KP
Case Streacom BC1 mini
Audio Device(s) Topping MX3
Power Supply Corsair RM750
Mouse R.A.T. DWS
Keyboard HAVIT KB487L / AKKO 3098 / Logitech G19
VR HMD HTC Vive
Benchmark Scores What's a "benchmark"?
Last time I remember Avira being good was before the year 2006, when it didn't exist as a mainstream product.
They are now owned by Norton, after being sold to a shady investment company. What do you expect? If you buy consumer trash you're the product, the device is only there to extract value from you.
 
Last edited:

TheLostSwede

News Editor
Joined
Nov 11, 2004
Messages
17,495 (2.40/day)
Location
Sweden
System Name Overlord Mk MLI
Processor AMD Ryzen 7 7800X3D
Motherboard Gigabyte X670E Aorus Master
Cooling Noctua NH-D15 SE with offsets
Memory 32GB Team T-Create Expert DDR5 6000 MHz @ CL30-34-34-68
Video Card(s) Gainward GeForce RTX 4080 Phantom GS
Storage 1TB Solidigm P44 Pro, 2 TB Corsair MP600 Pro, 2TB Kingston KC3000
Display(s) Acer XV272K LVbmiipruzx 4K@160Hz
Case Fractal Design Torrent Compact
Audio Device(s) Corsair Virtuoso SE
Power Supply be quiet! Pure Power 12 M 850 W
Mouse Logitech G502 Lightspeed
Keyboard Corsair K70 Max
Software Windows 10 Pro
Benchmark Scores https://valid.x86.fr/yfsd9w
Joined
Apr 21, 2010
Messages
576 (0.11/day)
System Name Home PC
Processor Ryzen 5900X
Motherboard Asus Prime X370 Pro
Cooling Thermaltake Contac Silent 12
Memory 2x8gb F4-3200C16-8GVKB - 2x16gb F4-3200C16-16GVK
Video Card(s) XFX RX480 GTR
Storage Samsung SSD Evo 120GB -WD SN580 1TB - Toshiba 2TB HDWT720 - 1TB GIGABYTE GP-GSTFS31100TNTD
Display(s) Cooler Master GA271 and AoC 931wx (19in, 1680x1050)
Case Green Magnum Evo
Power Supply Green 650UK Plus
Mouse Green GM602-RGB ( copy of Aula F810 )
Keyboard Old 12 years FOCUS FK-8100
I have TP-link W8960N .does it affect ?
 

TheLostSwede

News Editor
Joined
Nov 11, 2004
Messages
17,495 (2.40/day)
Location
Sweden
System Name Overlord Mk MLI
Processor AMD Ryzen 7 7800X3D
Motherboard Gigabyte X670E Aorus Master
Cooling Noctua NH-D15 SE with offsets
Memory 32GB Team T-Create Expert DDR5 6000 MHz @ CL30-34-34-68
Video Card(s) Gainward GeForce RTX 4080 Phantom GS
Storage 1TB Solidigm P44 Pro, 2 TB Corsair MP600 Pro, 2TB Kingston KC3000
Display(s) Acer XV272K LVbmiipruzx 4K@160Hz
Case Fractal Design Torrent Compact
Audio Device(s) Corsair Virtuoso SE
Power Supply be quiet! Pure Power 12 M 850 W
Mouse Logitech G502 Lightspeed
Keyboard Corsair K70 Max
Software Windows 10 Pro
Benchmark Scores https://valid.x86.fr/yfsd9w
Joined
Dec 26, 2020
Messages
382 (0.27/day)
System Name Incomplete thing 1.0
Processor Ryzen 2600
Motherboard B450 Aorus Elite
Cooling Gelid Phantom Black
Memory HyperX Fury RGB 3200 CL16 16GB
Video Card(s) Gigabyte 2060 Gaming OC PRO
Storage Dual 1TB 970evo
Display(s) AOC G2U 1440p 144hz, HP e232
Case CM mb511 RGB
Audio Device(s) Reloop ADM-4
Power Supply Sharkoon WPM-600
Mouse G502 Hero
Keyboard Sharkoon SGK3 Blue
Software W10 Pro
Benchmark Scores 2-5% over stock scores
Well pretty sketchy, good thing TP-Link is only good for the cheaper end of the router market. Would probably go for Asus or Netgear once some new standards roll out.
 

FreedomEclipse

~Technological Technocrat~
Joined
Apr 20, 2007
Messages
23,993 (3.74/day)
Location
London,UK
System Name DarnGosh Edition
Processor AMD 7800X3D
Motherboard MSI X670E GAMING PLUS
Cooling Thermalright AM5 Contact Frame + Phantom Spirit 120SE
Memory G.Skill Trident Z5 NEO DDR5 6000 CL32-38-38-96
Video Card(s) Asus Dual Radeon™ RX 6700 XT OC Edition
Storage WD SN770 1TB (Boot)| 2x 2TB WD SN770 (Gaming)| 2x 2TB Crucial BX500| 2x 3TB Toshiba DT01ACA300
Display(s) LG GP850-B
Case Corsair 760T (White) {1xCorsair ML120 Pro|5xML140 Pro}
Audio Device(s) Yamaha RX-V573|Speakers: JBL Control One|Auna 300-CN|Wharfedale Diamond SW150
Power Supply Seasonic Focus GX-850 80+ GOLD
Mouse Logitech G502 X
Keyboard Duckyshine Dead LED(s) III
Software Windows 11 Home
Benchmark Scores ლ(ಠ益ಠ)ლ
Yeah, and I'm the crazy one buying expensive gear from reputable vendors...

Do you really think Netgear, Linksys, Asus etc etc dont have backdoors to your router or collect your data anonymously and share with 3rd parties? Of course they do.
 
Joined
Feb 18, 2005
Messages
5,757 (0.80/day)
Location
Ikenai borderline!
System Name Firelance.
Processor Threadripper 3960X
Motherboard ROG Strix TRX40-E Gaming
Cooling IceGem 360 + 6x Arctic Cooling P12
Memory 8x 16GB Patriot Viper DDR4-3200 CL16
Video Card(s) MSI GeForce RTX 4060 Ti Ventus 2X OC
Storage 2TB WD SN850X (boot), 4TB Crucial P3 (data)
Display(s) 3x AOC Q32E2N (32" 2560x1440 75Hz)
Case Enthoo Pro II Server Edition (Closed Panel) + 6 fans
Power Supply Fractal Design Ion+ 2 Platinum 760W
Mouse Logitech G602
Keyboard Razer Pro Type Ultra
Software Windows 10 Professional x64
Do you really think Netgear, Linksys, Asus etc etc dont have backdoors to your router or collect your data anonymously and share with 3rd parties? Of course they do.
No, they don't. If they did, people would've noticed it and called them out for it.
 
Joined
Jul 10, 2017
Messages
2,671 (1.00/day)
No, they don't. If they did, people would've noticed it and called them out for it.
Yet even a quick search through most vulnerability databases reveal a shocking amount of flaws in their software. While it's all mostly patched by now, it trully shows how much these vendors 'care' about the security of their products. They do care about the brand image all right, but not real security per se.

It shouldn't have any kind of software like this on it, as it's an antique by now ;)


I doubt that would work, as it's got an ADSL2+ modem built in.
Come on, you know by now that I'm a sucker for networking gear (and any gear for that matter), and I just get an urge to hate bad security practices/zero security by design.
 
Joined
Feb 18, 2005
Messages
5,757 (0.80/day)
Location
Ikenai borderline!
System Name Firelance.
Processor Threadripper 3960X
Motherboard ROG Strix TRX40-E Gaming
Cooling IceGem 360 + 6x Arctic Cooling P12
Memory 8x 16GB Patriot Viper DDR4-3200 CL16
Video Card(s) MSI GeForce RTX 4060 Ti Ventus 2X OC
Storage 2TB WD SN850X (boot), 4TB Crucial P3 (data)
Display(s) 3x AOC Q32E2N (32" 2560x1440 75Hz)
Case Enthoo Pro II Server Edition (Closed Panel) + 6 fans
Power Supply Fractal Design Ion+ 2 Platinum 760W
Mouse Logitech G602
Keyboard Razer Pro Type Ultra
Software Windows 10 Professional x64
Yet even a quick search through most vulnerability databases reveal a shocking amount of flaws in their software.
That's nowhere near the same thing as the firmware being deliberately written to report users' browsing habits. Don't spread FUD by incorrectly conflating the two.
 
Joined
Oct 18, 2013
Messages
6,135 (1.52/day)
Location
Over here, right where you least expect me to be !
System Name The Little One
Processor i5-11320H @4.4GHZ
Motherboard AZW SEI
Cooling Fan w/heat pipes + side & rear vents
Memory 64GB Crucial DDR4-3200 (2x 32GB)
Video Card(s) Iris XE
Storage WD Black SN850X 4TB m.2, Seagate 2TB SSD + SN850 4TB x2 in an external enclosure
Display(s) 2x Samsung 43" & 2x 32"
Case Practically identical to a mac mini, just purrtier in slate blue, & with 3x usb ports on the front !
Audio Device(s) Yamaha ATS-1060 Bluetooth Soundbar & Subwoofer
Power Supply 65w brick
Mouse Logitech MX Master 2
Keyboard Logitech G613 mechanical wireless
Software Windows 10 pro 64 bit, with all the unnecessary background shitzu turned OFF !
Benchmark Scores PDQ
In fairness to TP-Link, their hardware isn't all that different from their competitors.
However, I would never, as I've said before here, use one of their devices with the default software on it, as a router facing the internet.
I put OpenWRT on both of my TP-Link devices and both of them are working better with OpenWRT than they did with the TP-Link firmware

In all fairness to them, many many years ago, I have found toilet paper's products, both hard & soft, to be just that, butt-wiper grade stuff....and have not touched them since and won't now either....

Almost every router vendor has had some issues here & there, both hardware, firmware, and software-wise, however, their attention to fixing them has been relatively good overall.

Over the past 8-10 years or so, I have found Netgear's (consumer) stuff to be somewhat better in this regard.

The fact the open-source firmware works better on tp's crap is both a testament to the OSS community, and big, black, bloody eye for tp IMHO :D
 
Low quality post by Max(IT)
Joined
May 10, 2020
Messages
738 (0.45/day)
Processor Intel i7 13900K
Motherboard Asus ROG Strix Z690-E Gaming
Cooling Arctic Freezer II 360
Memory 32 Gb Kingston Fury Renegade 6400 C32
Video Card(s) PNY RTX 4080 XLR8 OC
Storage 1 TB Samsung 970 EVO + 1 TB Samsung 970 EVO Plus + 2 TB Samsung 870
Display(s) Asus TUF Gaming VG27AQL1A + Samsung C24RG50
Case Corsair 5000D Airflow
Power Supply EVGA G6 850W
Mouse Razer Basilisk
Keyboard Razer Huntsman Elite
Benchmark Scores 3dMark TimeSpy - 26698 Cinebench R23 2258/40751
Trust in a Chinese company… sure
 

Auxityne

New Member
Joined
Jul 1, 2021
Messages
8 (0.01/day)
Well, they must have forgotten my particular model (Archer AX4400) because my DNS gateway shows no traffic to Avira. At all. Of any kind.

And pre-emptively blocking that domain results in no performance issues.
 
Joined
Jul 10, 2017
Messages
2,671 (1.00/day)
That's nowhere near the same thing as the firmware being deliberately written to report users' browsing habits. Don't spread FUD by incorrectly conflating the two.
Eh, sometimes developers just forget some administrative access. Who can blame them?
 
Joined
May 7, 2020
Messages
261 (0.16/day)
Well, they must have forgotten my particular model (Archer AX4400) because my DNS gateway shows no traffic to Avira. At all. Of any kind.

And pre-emptively blocking that domain results in no performance issues.
Only those ''High end'' router with home care service shoved in have the privilege of being deemed important enough for telemetry.
 
Joined
Jul 5, 2013
Messages
27,387 (6.61/day)
I remember the time when Avira was actually good and go to antivirus package. It was is Win9x days though...
It still is. One of the best. While I disagree with and find unacceptable TP-Link sharing peoples data, at least Avira is a reasonably trustworthy company. They could have been sharing with Symantec or some other pathetically awful company.

Forget they had been bought by NLL..
 
Last edited:
Joined
Dec 25, 2020
Messages
6,547 (4.64/day)
Location
São Paulo, Brazil
System Name "Icy Resurrection"
Processor 13th Gen Intel Core i9-13900KS Special Edition
Motherboard ASUS ROG MAXIMUS Z790 APEX ENCORE
Cooling Noctua NH-D15S upgraded with 2x NF-F12 iPPC-3000 fans and Honeywell PTM7950 TIM
Memory 32 GB G.SKILL Trident Z5 RGB F5-6800J3445G16GX2-TZ5RK @ 7600 MT/s 36-44-44-52-96 1.4V
Video Card(s) ASUS ROG Strix GeForce RTX™ 4080 16GB GDDR6X White OC Edition
Storage 500 GB WD Black SN750 SE NVMe SSD + 4 TB WD Red Plus WD40EFPX HDD
Display(s) 55-inch LG G3 OLED
Case Pichau Mancer CV500 White Edition
Power Supply EVGA 1300 G2 1.3kW 80+ Gold
Mouse Microsoft Classic Intellimouse
Keyboard Generic PS/2
Software Windows 11 IoT Enterprise LTSC 24H2
Benchmark Scores I pulled a Qiqi~
I have an Archer AX50, apparently it has the Trend Micro version of the HomeCare software. It is disabled, but it would be highly appreciated of TP-Link to come clean and issue FW updates to all affected devices. Their hardware is affordable and has been relatively reliable to me, so it would be a shame to lose them to shenanigans like this.
 
Joined
Jul 20, 2018
Messages
339 (0.15/day)
Well, Avira has bought by AVG if i remember correctly (or vicaversa). AVG had in the TOS, that they share data with 3rd party, i think Avira had it too. So it's not a big surprise for me if that is true in some way.
 
Joined
Nov 4, 2005
Messages
11,960 (1.72/day)
System Name Compy 386
Processor 7800X3D
Motherboard Asus
Cooling Air for now.....
Memory 64 GB DDR5 6400Mhz
Video Card(s) 7900XTX 310 Merc
Storage Samsung 990 2TB, 2 SP 2TB SSDs, 24TB Enterprise drives
Display(s) 55" Samsung 4K HDR
Audio Device(s) ATI HDMI
Mouse Logitech MX518
Keyboard Razer
Software A lot.
Benchmark Scores Its fast. Enough.
The only thing I trust TP Link for is Ethernet over power adapters, they are invisible and everything sent on the network has to go through a router that reports it.
 
Top