US States Sue TP-Link Over Router Security and Alleged Chinese State Ties
Share
TP-Link Systems is facing coordinated legal action from several US states over allegations that it misled consumers regarding the security of its routers and downplayed its operational ties to China.
Attorneys general from Florida, Iowa, Montana, and Nebraska filed the lawsuits on 6 October 2026, joining a legal challenge initiated by Texas earlier this year. The complaints allege that TP-Link’s marketing materials—which as recently as late 2025 claimed its HomeShield service provided a “100% safeguard”—overstated the actual protection provided to users.
The legal filings highlight that TP-Link devices have been targeted in major cyber-espionage campaigns, including those attributed to threat actors known as Volt Typhoon and Flax Typhoon. The states argue that several exploited models lacked automatic firmware updates or had reached end-of-life status without adequate consumer notification of the resulting security risks.
Technical Disclosures Reveal ISP Router Flaws
In tandem with the legal action, security researchers at SEC Consult have released technical details regarding five vulnerabilities tracked as CVE-2025-30237 through CVE-2025-30241. These flaws affect TP-Link’s Aginet line, a suite of mesh systems, routers, and modems specifically managed by Internet Service Providers (ISPs).
The most critical of these issues is an authentication bypass (CVE-2025-30237) in the device’s web server. An unauthenticated attacker on the same network could exploit this to create a super-administrator account and gain full control over the router without needing credentials. Other identified flaws include:
- CVE-2025-30241: A command injection vulnerability allowing authenticated users to execute commands with root privileges.
- CVE-2025-30239: Use of hardcoded encryption keys that could allow attackers to recover Wi-Fi credentials and ISP remote management passwords.
- CVE-2025-30240: A physical security flaw where a prepared USB drive could be used to read the device’s entire file system.
TP-Link identified 65 affected models and stated that firmware updates have been distributed to ISPs. Users are encouraged to check their ISP-provided management apps for available security patches.
Allegations of Undisclosed Foreign Influence
A significant portion of the lawsuits focuses on TP-Link’s corporate relationship with the Chinese government. The state complaints allege that the company failed to disclose that its Chinese affiliates are subject to national intelligence laws requiring cooperation with state security agencies. They also cite 2021 Chinese regulations that mandate the reporting of newly discovered vulnerabilities to the government before they are shared with the public or international partners.
TP-Link has dismissed the allegations as “baseless” and “built on false premises.” Steve Kovsky, TP-Link’s corporate affairs officer, stated the company has provided documentation to regulators showing that its US devices are manufactured in Vietnam and that the firm is not owned or controlled by any foreign government.
The controversy has reached federal regulators, with a coalition of 21 state attorneys general urging the Federal Communications Commission (FCC) to scrutinize the company’s practices. TP-Link is currently seeking conditional approval to sell new router models in the US, following FCC efforts to restrict equipment from foreign entities deemed to pose national security risks.




Leave a Reply