Skip to content
TP-Link Sued by Four More U.S. States Over Router Security and China Ties

TP-Link Sued by Four More U.S. States Over Router Security and China Ties

Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with  Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link denies the claims and says it will fight them in court.

TP-Link Systems is based in Irvine, California. Until a 2024 restructuring, it was affiliated with TP-Link Technologies, a Chinese company that the suits do not name as a defendant.

The complaints from Florida, Montana , and Nebraska do not allege that the Chinese government has obtained customers’ data through TP-Link. They describe that as a risk under Chinese law. Separately, they say state-backed hackers have exploited flaws in TP-Link routers.

Iowa’s announcement is worded more strongly in places. Attorney General Brenna Bird’s office said TP-Link firmware gives the Chinese government access to Iowans’ devices and data. The same release also describes that access as something that could happen.

The next day, 21 state attorneys general sent a letter to the Federal Communications Commission (FCC) about TP-Link’s effort to win approval for new router models in the U.S.

Three of the complaints also cite five flaws in TP-Link devices supplied by internet service providers (ISPs) to customers. Researchers published technical details of those flaws on October 8. Fixes exist, and they reach users through their ISP.

What The States Allege

The suits were filed in state courts under consumer-protection laws. The Florida, Montana, and Nebraska complaints share section headings and passages and make the same main claims.

The first is that TP-Link advertised security it did not deliver. The complaints quote TP-Link’s web page for HomeShield, its built-in network protection service, as saying it “covers all security scenarios.” The U.S. HomeShield page still said so on October 9.

The complaints set that against routers that were hacked and models that no longer get fixes. One example is two versions of the Archer AX21. TP-Link no longer updates them and says they reached end of life in May 2024, according to the complaints.

The second claim is that TP-Link overstated its split from China. The complaints quote the company as saying that the restructuring left it with “entirely different ownership, management, and operations” from those of TP-Link Technologies.

TP-Link and TP-Link Technologies together employed about 11,000 people in China, according to an April 2025 Bloomberg News report the states cite.

TP-Link says routers for the U.S. market are made in Vietnam. Only 0.5% of the parts used at its Vietnamese factory, by value, are sourced in Vietnam, and the rest are sourced from or through China, according to the complaints.

The third claim is that TP-Link’s privacy policies leave out a risk. Its Tether, Tapo, Deco and Kasa Smart apps collect email addresses, location and phone identifiers. A 2017 Chinese intelligence law could expose that data to Chinese intelligence agencies, according to the complaints.

Florida wants a permanent court order against the practices, the surrender of money made from them, and $10,000 for each willful violation. Montana seeks up to $10,000 per violation.

Nebraska also wants TP-Link ordered to tell buyers where its products and parts come from, about its ties to China, and about known vulnerabilities that have been exploited in its devices.

TP-Link’s Response

“The coordinated lawsuits are built on false premises. They do nothing to advance national security while unfairly penalizing an industry-leading U.S. company,” Steve Kovsky, the company’s corporate affairs officer, said in a statement issued the day the suits were filed.

For months, the statement said, TP-Link has given state regulators documents showing that its U.S. devices are made in Vietnam. It described itself as “an independent, U.S. company that is not owned or controlled by any foreign government.”

“We do not, and will not, share customer network data with foreign governments or unauthorized third parties,” it said.

What The Cited Attacks Show

The complaints point to real attacks in which hackers took over TP-Link routers.

Microsoft reported in 2024 that a hacking group it believes is in China had built a network of hacked small-office and home routers. The network was used for password-spray attacks, which try common passwords across many accounts.

TP-Link routers “make up most of this network,” Microsoft said, counting an average of 8,000 hacked devices active at any time.

The complaints themselves say devices from other brands were hacked as part of the same network.

The FBI said in April that Russian military intelligence hackers had compromised TP-Link routers through a flaw tracked as CVE-2023-50224. They changed the routers’ DNS settings and collected passwords and login tokens. TP-Link said in May that, with one exception, the products affected by that flaw had reached end of life.

The claim that Chinese state hackers used TP-Link routers in the Volt Typhoon and Flax Typhoon campaigns rests on testimony given in 2025. Rob Joyce, a former National Security Agency cybersecurity director, told a House committee that TP-Link routers “were among the various brands” exploited. His written testimony cites no source for that.

TP-Link disputed the testimony the same day, saying those campaigns “have no discernible preference for using TP-Link routers as a vector.”

None of the three complaints says TP-Link built a backdoor into its products. The one backdoor they name, Horse Shell, was placed on TP-Link routers by a Chinese state-backed hacking group, according to Check Point Research, which the complaints cite.

The complaints also note that the U.S. Department of Defense in June listed TP-Link Technologies as a Chinese military company. That is the Chinese firm. TP-Link Systems, the company being sued, is not on the list.

The FCC Letter

Since March 23, the FCC has barred new foreign-made consumer routers from the equipment authorization they need before they can be sold in the United States. The only exception is a router that wins a “Conditional Approval.”

Those approvals are decided by the Department of Homeland Security or the Department of Defense, which the FCC’s notice calls the Department of War.

The rule covers routers made in any foreign country, whatever the maker’s nationality. It applies by place of production, not by company.

Routers authorized before the rule can continue to receive software and firmware updates “that mitigate harm to U.S. consumers” until at least March 1, 2027, under an FCC waiver.

TP-Link said in April that its existing routers “remain fully authorized” and that it was “actively pursuing Conditional Approval for new products.”

The letter, led by Nebraska Attorney General Mike Hilgers and signed by 20 others, raises three concerns with the FCC. They are TP-Link’s security claims, its claims about separating from China and building routers in Vietnam, and what its privacy disclosures leave out about Chinese intelligence law.

The letter offers to work with the FCC. It does not ask the agency to deny, delay, or attach conditions to an approval.

“Consumers should be aware of these risks and the FCC should address them before authorizing these new routers for sale in U.S. markets,” Hilgers said in announcing the letter.

Montana Attorney General Austin Knudsen said he hoped the FCC would refuse the approval.

Flaws In ISP-Supplied Devices

Aginet is TP-Link’s line of mesh systems, routers, and modems that ISPs install for customers and keep up to date.

The complaints from Florida, Montana, and Nebraska cite five flaws in those devices as evidence that TP-Link’s security problems persist. TP-Link disclosed the flaws on August 10. On October 8, the SEC Consult researchers who found them published the technical details.

Together, the flaws “allowed an unauthenticated attacker on the same network to fully compromise the affected device,” SEC Consult said, and to run commands as root, the highest privilege level.

The attacker must first be able to reach the device’s web management interface. Neither SEC Consult nor TP-Link says whether that interface can be reached from the internet.

The main flaw, CVE-2025-30237, allows crafted web requests to bypass the login check. With it, an attacker without an account can create a “Superadmin” user and enable SSH remote access, according to SEC Consult.

CVE What It Allows What An Attacker Needs TP-Link Rating (CVSS 4.0, Out Of 10) Models Listed, Of 65
CVE-2025-30237 Privileged actions on the web interface without logging in Network access to the web management interface 8.7, High 56
CVE-2025-30238 A low-privileged account can create a high-privileged account and enable SSH A valid low-privileged login 8.6, High 59
CVE-2025-30239 Stored passwords can be decrypted because the keys are hardcoded per model. On some setups this includes the ISP’s remote-management credentials Access to the device’s stored configuration 8.5, High 65
CVE-2025-30240 Files on the device can be read through a crafted link on a USB stick Physical access to the USB port 5.1, Medium 33
CVE-2025-30241 Operating-system commands run with elevated privileges A login to the web interface 8.6, High 31

SEC Consult calls the set of flaws critical.

TP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to the CVE records TP-Link published. Versions that ISPs have customized are also affected, and TP-Link does not list those.

Owners may not be able to download the fix themselves. The updates are delivered through each ISP, and firmware for ISP versions “may not be publicly available for direct download,” TP-Link’s advisory says.

TP-Link advises users to check the device’s management interface or its app for a firmware update. If none is offered, they should contact their ISP.

SEC Consult lists no workaround. Neither advisory says how many devices have received the fix.

SEC Consult reported the flaws to TP-Link in December 2024, and TP-Link’s advisory followed nearly 20 months later. Most of the fixed firmware had been released by February 2026, according to SEC Consult’s timeline.

SEC Consult left the exploit commands out of its advisory. Neither advisory reports attacks that use the flaws. None of the five was in the U.S. Cybersecurity and Infrastructure Security Agency’s catalog of known exploited vulnerabilities as of its October 8 release.

Neither the complaints nor the advisories tie these flaws to the attacks described above, or to the allegations about China.

Source link