Four More U.S. States Sue TP-Link Over Router Security and China Ties

· Original article ↗

Summary

Florida, Iowa, Montana and Nebraska allege TP-Link misled consumers about router security, China ties and privacy risks. The company denies the claims; the article also details past router attacks and flaws in ISP-managed devices with fixes available through ISPs.

Key points

  • Four states filed lawsuits on October 6, bringing the total to five; TP-Link denies the allegations and says it will fight them.
  • The complaints allege misleading security and China-related claims, and that privacy disclosures omit risks under Chinese intelligence law. The suits do not allege that China obtained customer data.
  • The article describes prior compromises of TP-Link routers, including a botnet used for password-spray attacks and Russian military intelligence hackers exploiting CVE-2023-50224 to alter DNS settings and collect credentials.
  • Five flaws affecting TP-Link devices supplied by ISPs could let an unauthenticated attacker on the same network compromise a device and run commands as root; the article does not link them to the attacks or lawsuit allegations.
  • Fixes exist for the flaws, but updates for ISP-customized devices are delivered through the ISP; users should check for updates or contact their provider.
  • Twenty-one state attorneys general separately wrote to the FCC about TP-Link's bid for approval of new router models, raising concerns but not asking the agency to deny or delay approval.

Article Details

Event Type
Four U.S. states filed consumer-protection lawsuits against TP-Link Systems, alleging that it misled buyers about router security and its separation from China. The lawsuits cite vulnerabilities in TP-Link devices and past router compromises.
Impact
The states seek court orders, monetary remedies, and disclosures. Separately, five flaws in ISP-supplied TP-Link devices could allow an unauthenticated attacker with access to the web management interface to compromise affected devices and run commands as root. TP-Link says fixes exist and are delivered through ISPs; the article does not report attacks exploiting these five flaws.

MITRE ATT&CK

CVE

People

Threat Actors

Malware

Vendors

Products

AginetAginet is TP-Link's line of mesh systems, routers, and modems that ISPs install for customers and keep up to date.Archer AX21routers that were hacked and models that no longer get fixes. One example is two versions of the Archer AX21. TP-Link no longer updates them and says they reached end of life in May 2024, according to theDecoThe third claim is that TP-Link's privacy policies leave out a risk. Its Tether, Tapo, Deco and Kasa Smart apps collect email addresses, location and phone identifiers. A 2017 Chinese intelligence law could expose thatEBTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theECTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theEXTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theHBTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theHCTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theHomeShieldis that TP-Link advertised security it did not deliver. The complaints quote TP-Link's web page for HomeShield, its built-in network protection service, as saying it "covers all security scenarios." The U.S.HXTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theKasa SmartThe third claim is that TP-Link's privacy policies leave out a risk. Its Tether, Tapo, Deco and Kasa Smart apps collect email addresses, location and phone identifiers. A 2017 Chinese intelligence law could expose thatTapoThe third claim is that TP-Link's privacy policies leave out a risk. Its Tether, Tapo, Deco and Kasa Smart apps collect email addresses, location and phone identifiers. A 2017 Chinese intelligence law could expose thatTetherThe third claim is that TP-Link's privacy policies leave out a risk. Its Tether, Tapo, Deco and Kasa Smart apps collect email addresses, location and phone identifiers. A 2017 Chinese intelligence law could expose thatVXin its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to the CVE records TP-Link published.XCTP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to theXXlists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to the CVE

Countries

Industries

Related Articles