It always somewhat bugged me they used an actual domain for this, was there no other alternative like using a fake TLD? I'm not sure of what a router is entirely capable of doing, but if you could filter a request to "configure.tplink" or something that would make it far less likely to hijack the domain, that and the fact the domain didn't always work every time I would try it... or I couldn't remember it at times.