Addressing vulnerabilities of the M5350

Security Advisory
Updated 09-29-2019 09:37:47 AM 81165
This Article Applies to: 

We at TP-Link are aware of the security flaw in the 3G Mobile Wi-Fi Routers M5350, M5360 and M5250. After diagnosing the issue, we have identified a cross-site scripting (XSS) bug in the existing firmware. After sending a specific script command to the device via text message, the bug is triggered, replying with the device's administrator credentials in order to obtain access and control.

TP-Link has updated and released an update to the affected firmware to eliminate this vulnerability, and customers may download it directly from the product support page at the official TP-Link website (link here).

For the models that are affected by this XXS bug, we have provided updated, secure firmware that can be downloaded and installed to your device:

ž   3G Mobile Wi-Fi Router M5350 (Universal version) (South America version)

ž   3G Mobile Wi-Fi Router & Power Bank M5360 (Universal version)

ž   3G Mobile Wi-Fi Router M5250 (Universal version)

TP-Link strongly advises owners of these models to download these new firmware versions as soon as possible to avoid any security breach.

TP-Link is committed to serving customers while maintaining their security and apologizes for this security flaw. We will continue to prioritize the user moving forward.

For further questions or concerns, please contact TP-Link through the support page on the official website: https://www.tp-link.com/support/.

For further questions or concerns, please contact TP-Link through the support page on the official website: https://www.tp-link.com/support/.

Is this faq useful?

Your feedback helps improve this site.

Community

TP-Link Community

Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.

Visit the Community >

From United States?

Get products, events and services for your region.