Daniel Aleksandersen, a Norwegian tech expert, was the one who took up the issue further, due to an incident that happened to him. Specifically, he bought a TP-Link Network Repeater a month ago and after installing it, he went to TP-Link's Norwegian site to download the latest Firmware for the device. To his surprise, he saw that the latest Firmware was 2 versions behind other European countries (Denmark, Sweden).
Daniel Aleksandersen said that “You have about a 30% chance of finding older or no firmware at all when searching on the local TP-Link site.” Starting a search by selecting 9 random products from the company, he realized that only six countries (Czech Republic, Finland, France, Italy, Netherlands, Romania) had the latest firmware for the products he had chosen.
He believes that the company itself is not very interested in the security issues that its customers may have. On some of its sites there are no mailing lists or any notification system so that someone can be informed immediately in case there is a firmware update or a vulnerability. Also, some of its programs do not have the auto-update option. Therefore, in practice, if users want to feel safe, they should look at the TP-Link site on a daily basis for each of their products individually.
What is mainly worrying researchers and users of TP-Link products is an announcement regarding WIFI and specifically the KRACK that has the ability to break the WPA2 protocol. In this announcement (https://www.tp-link.com/en/faq-1970.html ) Tp-Link only mentions which of its products are vulnerable but not whether there is a firmware update that fixes them.
