UX prototype โ€” not a live TP-Link page. Content drafted from Phase 1 documents.

Vulnerability Disclosure Program

TP-Link welcomes coordinated reports of potential security vulnerabilities affecting our products, firmware, mobile apps, cloud services and websites. This page explains how to report, what happens next, and how we communicate with you.

What we commit to

Our response timeframes for reports submitted through the official channel.

5
business days
To acknowledge your report and confirm we have received it.
6
weeks โ€” maximum gap
We update you whenever there is meaningful progress, or at least this often, until the case closes.
1
tracking reference
Accepted reports receive a tracking ID you can quote in all follow-up communication.

How we handle your report

Five stages, from the moment you press submit to public advisory.

1

Receipt and acknowledgment

Your report is logged, assigned a tracking identifier and acknowledged. We do a first completeness review and create the case.

Report recordedCompleteness reviewAcknowledgment sentCase assigned
2

Triage and validation

Our Security Team assesses whether the issue is a valid vulnerability, identifies affected products, and sets a preliminary severity. We may come back to you for more detail.

Validate claimAssess reproducibilityIdentify affected versionsPreliminary severity
3

Impact assessment and product scope

We work with engineering and product teams to determine the full scope: which firmware, apps or cloud services are affected, how exploitable the issue is, and how many customers are exposed.

Confirm scopeEvaluate exploitabilityCustomer exposureRemediation priority
4

Remediation and mitigation

Engineering develops, tests and validates fixes, mitigations or configuration guidance. Where appropriate we reserve a CVE identifier. You may be invited to verify a beta build.

Develop fixValidation testingRelease planningReserve CVE
5

Publication and coordinated disclosure

We publish a security advisory where appropriate, release the fix, update CVE records, and coordinate the disclosure date with you.

Publish advisoryRelease fixUpdate CVECoordinate with researcher

Secure reporting

If your report contains exploit details, proof-of-concept code or customer-impacting information.

TP-Link supports encrypted submissions using OpenPGP (PGP/GPG). Paste your own public key in the report form if you want encrypted replies from us, and use our published key for sensitive material.

โฌ‡ Download TP-Link PGP public key

Coordinated disclosure expectations

What we ask of you, so the process stays safe for everyone including our customers.

โœ“Comply with applicable laws and regulations while conducting research.
โœ“Test against the latest publicly released firmware or app version.
โœ“Submit your findings in English.
โœ“Use this reporting channel โ€” other channels may not be monitored.
โœ“Do not access, modify or expose data belonging to TP-Link customers, users, employees or systems.
โœ“Hold public disclosure until a mutually agreed date, or until a fix or mitigation is available.

Disclosure policy

TP-Link generally does not publicly disclose vulnerabilities affecting our products or services until the investigation is complete and appropriate fixes, mitigations or workarounds are available.

We may accelerate public disclosure where there is evidence of active exploitation, significant customer impact, or where law or regulation requires earlier communication.

Found something?

The form takes about 5 minutes for a first report. You can add technical detail later.

Report a vulnerability โ†’