Post-20250919 router admin-surface audit (disable WAN admin, WPS, UPnP, cloud binding) #108
Labels
No labels
burndown-2026-06
burndown-2026-08
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/advocate
role/director
role/exec
role/frontend
role/gamedev
role/human
role/platform
role/qa
role/science
role/sysadmin
state
ambient
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/infrastructure#108
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
The TP-Link Archer A20 ships with several admin-surface defaults that are unsafe by modern threat-model standards. After the 20250919 firmware upgrade (tracked separately by the session that filed this issue), the router's admin surface needs an end-to-end audit and lockdown sweep.
Scope - in
/coilysiren/home/tplink-admin-password(already anticipated by #107).Scope - out
Why now
Router CVE = pre-auth, pre-LAN, owns DNS+DHCP+gateway+TLS-MITM surface for the whole home network. Highest-leverage hardening surface on Kai's stack.
Filed by Claude.