Four More U.S. States Sue TP-Link Over Router Security and China Ties

Summary
Florida, Iowa, Montana and Nebraska allege TP-Link misled consumers about router security, China ties and privacy risks. The company denies the claims; the article also details past router attacks and flaws in ISP-managed devices with fixes available through ISPs.
Key points
- Four states filed lawsuits on October 6, bringing the total to five; TP-Link denies the allegations and says it will fight them.
- The complaints allege misleading security and China-related claims, and that privacy disclosures omit risks under Chinese intelligence law. The suits do not allege that China obtained customer data.
- The article describes prior compromises of TP-Link routers, including a botnet used for password-spray attacks and Russian military intelligence hackers exploiting CVE-2023-50224 to alter DNS settings and collect credentials.
- Five flaws affecting TP-Link devices supplied by ISPs could let an unauthenticated attacker on the same network compromise a device and run commands as root; the article does not link them to the attacks or lawsuit allegations.
- Fixes exist for the flaws, but updates for ISP-customized devices are delivered through the ISP; users should check for updates or contact their provider.
- Twenty-one state attorneys general separately wrote to the FCC about TP-Link's bid for approval of new router models, raising concerns but not asking the agency to deny or delay approval.
Article Details
- Event Type
- Four U.S. states filed consumer-protection lawsuits against TP-Link Systems, alleging that it misled buyers about router security and its separation from China. The lawsuits cite vulnerabilities in TP-Link devices and past router compromises.
- Impact
- The states seek court orders, monetary remedies, and disclosures. Separately, five flaws in ISP-supplied TP-Link devices could allow an unauthenticated attacker with access to the web management interface to compromise affected devices and run commands as root. TP-Link says fixes exist and are delivered through ISPs; the article does not report attacks exploiting these five flaws.
MITRE ATT&CK
CVE
CVE-2023-50224that Russian military intelligence hackers had compromised TP-Link routers through a flaw tracked as CVE-2023-50224. They changed the routers' DNS settings and collected passwords and login tokens. TP-Link said in MayCVE-2025-30237The main flaw, CVE-2025-30237, allows crafted web requests to bypass the login check. With it, an attacker without an account can create a "Superadmin" user and enable SSH remote access, according to SEC Consult.
People
Austin KnudsenMontana Attorney General who said he hoped the FCC would refuse approval for TP-Link's new routers.Brenna BirdIowa Attorney General whose office issued a statement about alleged access to Iowans' devices and data.Mike HilgersNebraska Attorney General who led the letter from state attorneys general to the FCC.Rob JoyceFormer National Security Agency cybersecurity director who testified that TP-Link routers were among brands exploited in the Volt Typhoon and Flax Typhoon campaigns.Steve KovskyTP-Link corporate affairs officer who disputed the lawsuits' claims in a company statement.
Threat Actors
Malware
Vendors
TP-Link SystemsFour more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyersTP-Link TechnologiesTP-Link Systems is based in Irvine, California. Until a 2024 restructuring, it was affiliated with TP-Link Technologies, a Chinese company that the suits do not name as a defendant.
Products
AginetAginet is TP-Link's line of mesh systems, routers, and modems that ISPs install for customers and keep up to date.Archer AX21routers that were hacked and models that no longer get fixes. One example is two versions of the Archer AX21. TP-Link no longer updates them and says they reached end of life in May 2024, according to theDecoThe third claim is that TP-Link's privacy policies leave out a risk. Its Tether, Tapo, Deco and Kasa Smart apps collect email addresses, location and phone identifiers. A 2017 Chinese intelligence law could expose thatEBTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theECTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theEXTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theHBTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theHCTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theHomeShieldis that TP-Link advertised security it did not deliver. The complaints quote TP-Link's web page for HomeShield, its built-in network protection service, as saying it "covers all security scenarios." The U.S.HXTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theKasa SmartThe third claim is that TP-Link's privacy policies leave out a risk. Its Tether, Tapo, Deco and Kasa Smart apps collect email addresses, location and phone identifiers. A 2017 Chinese intelligence law could expose thatTapoThe third claim is that TP-Link's privacy policies leave out a risk. Its Tether, Tapo, Deco and Kasa Smart apps collect email addresses, location and phone identifiers. A 2017 Chinese intelligence law could expose thatTetherThe third claim is that TP-Link's privacy policies leave out a risk. Its Tether, Tapo, Deco and Kasa Smart apps collect email addresses, location and phone identifiers. A 2017 Chinese intelligence law could expose thatVXin its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to the CVE records TP-Link published.XCTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theXXlists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to the CVE
Countries
Chinaallege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link denies the claims and says it will fight them in court.RussiaUnited Statesconsumer routers from the equipment authorization they need before they can be sold in the United States. The only exception is a router that wins a "Conditional Approval."VietnamTP-Link says routers for the U.S. market are made in Vietnam. Only 0.5% of the parts used at its Vietnamese factory, by value, are sourced in Vietnam, and the rest are sourced from or through China, according to the