Download Privacy Needle App

Type to search

Cybersecurity

US States Sue TP-Link Over Router Security and Alleged Chinese State Ties

Share

TP-Link Systems is facing coordinated legal action from several US states over allegations that it misled consumers regarding the security of its routers and downplayed its operational ties to China.

Attorneys general from Florida, Iowa, Montana, and Nebraska filed the lawsuits on 6 October 2026, joining a legal challenge initiated by Texas earlier this year. The complaints allege that TP-Link’s marketing materials—which as recently as late 2025 claimed its HomeShield service provided a “100% safeguard”—overstated the actual protection provided to users.

The legal filings highlight that TP-Link devices have been targeted in major cyber-espionage campaigns, including those attributed to threat actors known as Volt Typhoon and Flax Typhoon. The states argue that several exploited models lacked automatic firmware updates or had reached end-of-life status without adequate consumer notification of the resulting security risks.

Technical Disclosures Reveal ISP Router Flaws

In tandem with the legal action, security researchers at SEC Consult have released technical details regarding five vulnerabilities tracked as CVE-2025-30237 through CVE-2025-30241. These flaws affect TP-Link’s Aginet line, a suite of mesh systems, routers, and modems specifically managed by Internet Service Providers (ISPs).

The most critical of these issues is an authentication bypass (CVE-2025-30237) in the device’s web server. An unauthenticated attacker on the same network could exploit this to create a super-administrator account and gain full control over the router without needing credentials. Other identified flaws include:

  • CVE-2025-30241: A command injection vulnerability allowing authenticated users to execute commands with root privileges.
  • CVE-2025-30239: Use of hardcoded encryption keys that could allow attackers to recover Wi-Fi credentials and ISP remote management passwords.
  • CVE-2025-30240: A physical security flaw where a prepared USB drive could be used to read the device’s entire file system.

TP-Link identified 65 affected models and stated that firmware updates have been distributed to ISPs. Users are encouraged to check their ISP-provided management apps for available security patches.

Allegations of Undisclosed Foreign Influence

A significant portion of the lawsuits focuses on TP-Link’s corporate relationship with the Chinese government. The state complaints allege that the company failed to disclose that its Chinese affiliates are subject to national intelligence laws requiring cooperation with state security agencies. They also cite 2021 Chinese regulations that mandate the reporting of newly discovered vulnerabilities to the government before they are shared with the public or international partners.

TP-Link has dismissed the allegations as “baseless” and “built on false premises.” Steve Kovsky, TP-Link’s corporate affairs officer, stated the company has provided documentation to regulators showing that its US devices are manufactured in Vietnam and that the firm is not owned or controlled by any foreign government.

The controversy has reached federal regulators, with a coalition of 21 state attorneys general urging the Federal Communications Commission (FCC) to scrutinize the company’s practices. TP-Link is currently seeking conditional approval to sell new router models in the US, following FCC efforts to restrict equipment from foreign entities deemed to pose national security risks.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.