Five U.S. states have sued router maker TP-Link Systems, accusing the company of misleading consumers about the security of its devices, its business ties to China, and the handling of customer data.
Florida, Iowa, Montana and Nebraska filed their lawsuits on October 6, joining Texas, which brought a separate case in February. TP-Link has rejected the allegations, calling the coordinated lawsuits based on false premises and saying it will defend itself in court.
TP-Link Systems is headquartered in Irvine, California. Before a corporate restructuring in 2024, it was affiliated with TP-Link Technologies, a Chinese company that is not named as a defendant in the lawsuits. The states argue that TP-Link has overstated how completely the U.S. business has separated itself from its former Chinese affiliate.
The complaints filed by Florida, Montana and Nebraska do not claim that the Chinese government has already obtained customers’ data through TP-Link. Instead, they argue that Chinese intelligence laws could create a risk. Iowa’s announcement makes stronger claims in some passages, alleging that TP-Link firmware gives Chinese authorities access to devices and data, while also describing that access as a potential risk.
The lawsuits focus on three main issues: security claims, the company’s separation from China, and privacy disclosures. The states challenge TP-Link’s marketing of HomeShield, its built-in network protection service, which the company has described as covering “all security scenarios.” They argue that this language is misleading given reports of compromised routers and devices that no longer receive security updates.
One example cited in the complaints is certain versions of the Archer AX21 router, which TP-Link reportedly stopped updating after declaring them end-of-life in May 2024. The states also question the company’s statements that its restructuring created entirely different ownership, management and operations from TP-Link Technologies.
The complaints cite an April 2025 Bloomberg News report stating that the two companies together employed approximately 11,000 people in China. They also challenge TP-Link’s claims about manufacturing in Vietnam, arguing that only a small share of the parts used at its Vietnamese factory, measured by value, are sourced locally, with the remainder coming from or through China.
Privacy is another major concern. According to the complaints, TP-Link’s Tether, Tapo, Deco and Kasa Smart apps collect information such as email addresses, location data and phone identifiers. The states argue that China’s 2017 intelligence law could expose this information to Chinese intelligence agencies.
TP-Link denies sharing customer network data with foreign governments or unauthorized third parties. In a statement issued when the lawsuits were announced, the company said it had provided regulators with documents showing that its U.S. devices are manufactured in Vietnam. It described itself as an independent American company that is not owned or controlled by a foreign government.
The lawsuits also point to previous cyberattacks involving compromised TP-Link routers. Microsoft reported in 2024 that a hacking group believed to be operating from China had built a network of compromised home and small-office routers, most of which were TP-Link devices. The network reportedly averaged around 8,000 active compromised devices at a time and was used for password-spraying attacks.
In a separate case, the FBI said Russian military intelligence hackers had exploited a vulnerability tracked as CVE-2023-50224 to compromise TP-Link routers, change their DNS settings and collect passwords and login tokens. TP-Link later said that, with one exception, the affected products had reached the end of their support life.
The complaints also refer to testimony from former National Security Agency cybersecurity director Rob Joyce concerning the Volt Typhoon and Flax Typhoon hacking campaigns. Joyce told a congressional committee in 2025 that TP-Link routers were among the brands exploited. TP-Link disputed the suggestion that those campaigns showed a particular preference for its devices.
Importantly, the complaints do not allege that TP-Link deliberately built a backdoor into its products. They cite the Horse Shell backdoor as malware installed on TP-Link routers by a Chinese state-backed hacking group, according to research from Check Point Research. The complaints also refer to the U.S. Department of Defense’s listing of TP-Link Technologies as a Chinese military company, but that listing concerns the Chinese firm, not TP-Link Systems, which is being sued.
The legal action comes as the Federal Communications Commission reviews the authorization of new router models for the U.S. market. On October 7, 21 state attorneys general sent a letter to the FCC raising concerns about TP-Link’s security claims, its corporate separation from China, its manufacturing arrangements and its privacy disclosures. The letter did not explicitly ask the agency to reject or delay approval, although Montana’s attorney general said he hoped the FCC would refuse it.
The FCC’s restrictions on new foreign-made consumer routers, introduced on March 23, apply based on where devices are manufactured rather than the nationality of their makers. New products generally need conditional approval to qualify for authorization, while a waiver allows previously authorized routers to receive security updates until at least March 1, 2027.
Separate concerns involve vulnerabilities in TP-Link’s Aginet product line, which includes routers, modems and mesh networking equipment supplied and maintained by internet service providers. Researchers at SEC Consult published technical details of five vulnerabilities on October 8 after TP-Link disclosed them in August.
The flaws affect multiple device families and could allow attackers with access to a device’s web management interface or other required access to compromise the equipment. The most serious, CVE-2025-30237, allows an unauthenticated attacker who can reach the management interface to bypass login checks, create a privileged administrator account and enable SSH remote access.
The other vulnerabilities involve privilege escalation, the decryption of stored passwords, file access through a crafted link on a USB drive, and operating-system command execution with elevated privileges. TP-Link’s published ratings place four of the five flaws in the high-severity category, while the USB-related issue is rated medium severity.
The affected products include 65 models across several router, mesh networking, fiber and DSL device families, although the vulnerabilities do not affect every model in the same way. Some devices supplied by ISPs use customized firmware that may not be available for direct public download.
TP-Link says fixes are available, with updates delivered through the relevant internet service providers. The company advises customers to check their device’s management interface or companion app for firmware updates and contact their ISP if no update is available.
SEC Consult has not reported attacks exploiting these five vulnerabilities, and the published advisories do not connect them to the cyberattacks cited in the lawsuits. The available information also does not establish that these flaws are linked to the allegations concerning China.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The lawsuits now place TP-Link’s security practices, corporate structure and privacy disclosures under legal scrutiny. The company disputes the allegations, and the claims will need to be assessed through the legal process.
Five U.S. States Sue TP-Link Over Router Security and China Ties



