What we commit to
Our response timeframes for reports submitted through the official channel.
How we handle your report
Five stages, from the moment you press submit to public advisory.
Receipt and acknowledgment
Your report is logged, assigned a tracking identifier and acknowledged. We do a first completeness review and create the case.
Triage and validation
Our Security Team assesses whether the issue is a valid vulnerability, identifies affected products, and sets a preliminary severity. We may come back to you for more detail.
Impact assessment and product scope
We work with engineering and product teams to determine the full scope: which firmware, apps or cloud services are affected, how exploitable the issue is, and how many customers are exposed.
Remediation and mitigation
Engineering develops, tests and validates fixes, mitigations or configuration guidance. Where appropriate we reserve a CVE identifier. You may be invited to verify a beta build.
Publication and coordinated disclosure
We publish a security advisory where appropriate, release the fix, update CVE records, and coordinate the disclosure date with you.
Secure reporting
If your report contains exploit details, proof-of-concept code or customer-impacting information.
TP-Link supports encrypted submissions using OpenPGP (PGP/GPG). Paste your own public key in the report form if you want encrypted replies from us, and use our published key for sensitive material.
โฌ Download TP-Link PGP public keyCoordinated disclosure expectations
What we ask of you, so the process stays safe for everyone including our customers.
Disclosure policy
TP-Link generally does not publicly disclose vulnerabilities affecting our products or services until the investigation is complete and appropriate fixes, mitigations or workarounds are available.
We may accelerate public disclosure where there is evidence of active exploitation, significant customer impact, or where law or regulation requires earlier communication.
Found something?
The form takes about 5 minutes for a first report. You can add technical detail later.
Report a vulnerability โ