Post-20250919 router admin-surface audit (disable WAN admin, WPS, UPnP, cloud binding) #108
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
The TP-Link Archer A20 ships with several admin-surface defaults that are unsafe by modern threat-model standards. After the 20250919 firmware upgrade (tracked separately by the session that filed this issue), the router's admin surface needs an end-to-end audit and lockdown sweep.
Scope - in
/coilysiren/home/tplink-admin-password(already anticipated by #107).Scope - out
Why now
Router CVE = pre-auth, pre-LAN, owns DNS+DHCP+gateway+TLS-MITM surface for the whole home network. Highest-leverage hardening surface on Kai's stack.
Filed by Claude.