Vulnerability scan

Team,
See also attached image:
We just finished a vulnerability scan against our TL-ER7206 v1.0 (firmware 1.2).
There are 2 issues that would prevent us from onboarding a (potential) customer because of PCI-DSS compliance.
One issue is related to the embedded version of nginx and the other is about SSL3/TLS1 support.
Please allow:
- an upgrade of the embedded nginx server and
- a configurable option disabling support for SSL3/TLS1
Feel free to contact me of there are any questions.
With warm regards - Will
=====
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content

Dear @ITV,
ITV wrote
See also attached image:
We just finished a vulnerability scan against our TL-ER7206 v1.0 (firmware 1.2).
There are 2 issues that would prevent us from onboarding a (potential) customer because of PCI-DSS compliance.
One issue is related to the embedded version of nginx and the other is about SSL3/TLS1 support.
Please allow:
- an upgrade of the embedded nginx server and
- a configurable option disabling support for SSL3/TLS1
Feel free to contact me of there are any questions.
Thanks for posting your concern on TP-Link Community!
Regarding the Nginx version, here is a similar feedback for your information.
ER605 Standalone Configuration & Reported Nessus Vulnerability
As for the support for SSL3/TLS1, I'd like to escalate your case to the TP-Link support team for further investigation.
They will reach you via your registered email address shortly, please pay attention to your email box later.
Update on June 15, 2022:
The firmware 1.2.1 has been released to fix the vulnerability caused by supporting SSL2.0/3.0.
- Copy Link
- Report Inappropriate Content

Dear @ITV,
ITV wrote
See also attached image:
We just finished a vulnerability scan against our TL-ER7206 v1.0 (firmware 1.2).
There are 2 issues that would prevent us from onboarding a (potential) customer because of PCI-DSS compliance.
One issue is related to the embedded version of nginx and the other is about SSL3/TLS1 support.
Please allow:
- an upgrade of the embedded nginx server and
- a configurable option disabling support for SSL3/TLS1
Feel free to contact me of there are any questions.
Thanks for posting your concern on TP-Link Community!
Regarding the Nginx version, here is a similar feedback for your information.
ER605 Standalone Configuration & Reported Nessus Vulnerability
As for the support for SSL3/TLS1, I'd like to escalate your case to the TP-Link support team for further investigation.
They will reach you via your registered email address shortly, please pay attention to your email box later.
Update on June 15, 2022:
The firmware 1.2.1 has been released to fix the vulnerability caused by supporting SSL2.0/3.0.
- Copy Link
- Report Inappropriate Content
Thank you for your to the point response. Looking forward to the february update and the support team on the SSL/TLS issue.
With warm regards - Will
- Copy Link
- Report Inappropriate Content

Information
Helpful: 0
Views: 1351
Replies: 2
Voters 0
No one has voted for it yet.