VMTech
Discuss a project →

Four States Bring TP-Link Router Security Claims to Court

Four States Bring TP-Link Router Security Claims to Court

Florida, Iowa, Montana and Nebraska sued TP-Link Systems on October 6, joining Texas, which filed a case in February. The states allege that the Irvine, California-based router maker misrepresented the security of its devices and the extent of its separation from China. TP-Link denies the allegations and says it will fight the coordinated lawsuits.

The actions were filed under state consumer-protection laws. Florida, Montana and Nebraska make closely aligned claims about TP-Link's security marketing, its 2024 restructuring from Chinese affiliate TP-Link Technologies, and privacy disclosures for the Tether, Tapo, Deco and Kasa Smart apps.

Claims focus on security, ownership and disclosures

The complaints challenge HomeShield marketing that says the built-in network protection service “covers all security scenarios.” They contrast that statement with compromised TP-Link routers and products that have reached end of life. Two Archer AX21 versions, for example, stopped receiving updates after reaching end of life in May 2024, the complaints say.

The states also dispute whether the restructuring produced the operational separation described by TP-Link. The complaints cite a reported combined workforce of about 11,000 people in China and say that, although U.S.-market routers are made in Vietnam, most component value at the Vietnamese factory is sourced from or through China.

They further argue that privacy notices omit a risk associated with Chinese intelligence law and the data collected by TP-Link applications. The Florida, Montana and Nebraska filings do not allege that the Chinese government obtained customer data. None of the three complaints alleges that TP-Link inserted a backdoor into its products.

TP-Link contests the allegations

Steve Kovsky, TP-Link's corporate affairs officer, said the suits rest on false premises and unfairly penalize an independent U.S. company. TP-Link said it had supplied regulators with documents showing its U.S. devices are made in Vietnam, that it is not owned or controlled by a foreign government, and that it does not share customer network data with foreign governments or unauthorized third parties.

The filings cite prior attacks on TP-Link equipment, including Microsoft reporting in 2024 that TP-Link routers made up most of a network of compromised small-office and home routers used for password-spray activity. The FBI also said Russian military intelligence hackers exploited CVE-2023-50224 to alter DNS settings and collect passwords and login tokens. TP-Link said most affected products had reached end of life.

ISP-managed devices have five disclosed flaws

Florida, Montana and Nebraska additionally cite five vulnerabilities in TP-Link Aginet equipment supplied and maintained by internet service providers. Researchers at SEC Consult published technical details on October 8 after TP-Link disclosed the issues on August 10. The most serious, CVE-2025-30237, can allow an unauthenticated attacker who can reach the web management interface to perform privileged actions, create a Superadmin user and enable SSH access.

TP-Link lists 65 affected models across mesh, router, fiber and DSL product lines. Firmware fixes exist, but ISP-customized versions may not be available for direct download. SEC Consult reported no known attacks using the five vulnerabilities, and the advisories do not establish a link between them and the attacks referenced in the lawsuits.

For businesses, the cases reinforce the need to verify router support dates, identify who controls firmware distribution, and document escalation routes with providers when network equipment is ISP-managed.

#cybersecurity#routersecurity#vulnerability#networksecurity
Open analytics
On the site 1 views
min read 4 09.10.2026
Instagram

Four States Bring TP-Link Router Security Claims to Court

Open the post on Instagram ↗