Is it safe to buy a used router?

I currently have a good offer for a used TP-Link Archer C2600. This is device with powerful hardware, unfortunately you can't buy new ones of them (at least not for an affordable price).

So I'm thinking about buying this used one, but how can I be sure it isn't compromised regarding software? Currently the stock firmware is installed, so will I be safe when installing openwrt because everything in the flash is overwritten anyway?

Sorry if that's an boob question, but I'm a bit anxious about my personal network being compromised.

It's safe, depending on the size of your tinfoil hat you might want to reflash it instead of just doing a factory reset.

I have a vague memory of some quirks specific for this model but you have to do your own research.

And what about a brand new one ??????

Almost everything is overwritten. Usually the bootloader is left intact (but you can assume it to be genuine if it boots stock firmware and if the PCB hasn't been tampered with) and some models also have some sort of vendor config partition which is sometimes left alone by OpenWrt. This partition might contain settings from a previous OEM firmware install like wifi keys similar. But if at all that wouldn't be a problem for you but for the person selling the device.

If YOU are the one who installs openwrt from a known good source, then you are pretty much good to go.


Thank you very much @jow! That's what I was hoping to hear.

Just in case - is there a way to restore the bootloader partition? Maybe by flashing the stock firmware?

@Pferdebockwurst I bought an used C2600 some months ago, and is working great (in my case is working as dumb AP, not as router). If you want (I did it!!!), you can reflash it with stock firmware before installing OpenWRT, follow the guide found here [Solved] Reset Archer C2600 to original firmware

After that, get the lastest dev OpenWRT firmware version found here and flash it (directly from stock GUI), then "enjoy" your new router!!!

Thanks for linking these interesting topics. But how do you flash it via stock GUI, I thought openwrt wouldn't be accepted as a valid firmware update?

The OpenWrt wiki isn't very informative about this question. Try it with the OEM web gui, and if it doesn't work, use the TFTP method which the wiki suggests will work:

It works in C2600, tested by myself many times.

Well that would really surprise, as I've read this nowhere else. But you might simply have another revision or something like that. You're lucky because you obviously don't have to solder to get a serial connection.

If it's rejecting it, rename the file to "ArcherC2600_1.0_tp_recovery.bin" before flashing.

To prevent misunderstanding, do you mean flashing via GUI or TFTP?

