TP-Link CPE710 v1
TP-Link CPE710 is an outdoor wireless CPE for 5 GHz with one Ethernet port based on the AP152 reference board.
The device has a built-in 23dBi high-gain directional 2×2 MIMO antenna and a dedicated metal reflector, with a beamwidth of 9° (Azimuth) and 7° (Elevation). The radio support MCS 0-9 (up through 256 QAM) for devices and paths that are compatible with those high-density modulations, up to 867Mbps. Supports DFS channels, from channel 36 up to 173 (may vary on each region).
This is a router based on a Qualcomm QCA9563-AL3A MIPS 74kc @ 775MHz.
It has one PoE 1Gbps LAN port. Power comes from its external 24V, 0.5A power adapter.
Supported Versions
Hardware Highlights
Installation
OEM easy installation
- Apply factory image via web-gui.
OEM installation using the TFTP + serial method
- To get to TFTP recovery just hold reset button while powering on for around 30-40 seconds and release.
- Stock device TFTP address: 192.168.0.254
- Set ip address of TFTP server to 192.168.0.100
- Put OpenWrt factory image to tftp folder and rename it to
recovery.bin - Stop device while booting in u-boot
- Run command
run flashimg - Run command
setenv boot_part 1 - Run command
saveenv - Reset
Upgrading OpenWrt
LuCI Web Upgrade Process
- Browse to
http://192.168.1.1/cgi-bin/luci/mini/system/upgrade/LuCI Upgrade URL - Upload image file for sysupgrade to LuCI
- Wait for reboot
Terminal Upgrade Process
If you don't have a GUI (LuCI) available, you can alternatively upgrade via the command line. Note: It is important that you put the firmware image into the ramdisk (/tmp) before you start flashing.
sysupgrade
Login as root via SSH on 192.168.1.1, then enter the following commands:
cd /tmp wget https://downloads.openwrt.org/snapshots/targets/ath79/generic/openwrt-ath79-generic-tplink_cpe710-v1-squashfs-sysupgrade.bin sysupgrade /tmp/openwrt-ath79-generic-tplink_cpe710-v1-squashfs-sysupgrade.bin
Technical Details
Once the device is updated to version 1.1.2 Build 20251113 or later, the U-Boot bootloader is modified to enforce strict RSA signature verification:
- TFTP Recovery: The bootloader will check the signature of the image transferred via TFTP. Since OpenWrt images are not signed by TP-Link, they will be rejected during the process.
- UART Serial Access: Even with physical access via UART, the bootloader remains locked. It will not execute or flash unsigned binaries, making it impossible to bypass the lock or downgrade to an older, unlocked version.
- No Downgrade Path: There is currently no known software-based method to revert the bootloader once it has been upgraded to the locked version.
<note warning> If you intend to use OpenWrt, DO NOT update to the vendor firmware version 1.1.2 or newer. Check your current version in the Web UI before attempting any installation. </note> ++++
Hardware
Info
