Menu
CYBERSECURITY NEWS

Four More U.S. States Sue TP-Link Over Router Security Claims

Uday Patil Oct 9, 2026 9 min read 8 views
Four More U.S. States Sue TP-Link Over Router Security Claims

TP-Link router lawsuit activity has expanded after Florida, Iowa, Montana and Nebraska filed separate cases accusing TP-Link Systems of misleading consumers about router security, privacy risks and its relationship with China.

The lawsuits were filed on October 6, 2026, bringing the number of U.S. states suing TP-Link Systems to five after Texas filed a separate case in February.

The allegations focus on three main areas: whether TP-Link overstated the security of its routers, whether it accurately described its separation from China-based operations, and whether its privacy disclosures adequately explain potential risks connected to Chinese intelligence law.

TP-Link strongly denies the allegations and says the lawsuits are based on false premises.

For broader coverage of state-linked cyber risk and geopolitical security concerns, see our Nation-State Cyber Warfare and APT Threats Hub.

Key takeaway: The lawsuits do not prove that TP-Link built a backdoor into its routers or that the Chinese government obtained customer data through TP-Link. They allege that consumers were not given enough information about security, supply-chain and China-related risks.

Which U.S. States Are Suing TP-Link?

The latest lawsuits were filed by:

  • Florida
  • Iowa
  • Montana
  • Nebraska

Texas filed a separate lawsuit against TP-Link Systems in February 2026.

Together, the cases represent growing legal and regulatory pressure on the router maker in the United States.

What Do the States Allege?

The complaints differ in wording, but several common allegations appear across the cases.

Florida, Montana and Nebraska argue that TP-Link marketed its routers as highly secure while failing to adequately disclose known security weaknesses and real-world exploitation involving some TP-Link devices.

The states also challenge TP-Link’s description of its corporate separation from its former China-based affiliate and raise concerns about continuing research, manufacturing and supply-chain links to China.

Iowa’s announcement uses stronger language and alleges that TP-Link firmware could give the Chinese government access to devices and user data.

That allegation should be treated as a claim made by the state, not as an independently established fact.

No Allegation of a Built-In Chinese Government Backdoor

One important distinction is that the complaints cited in public reporting do not say TP-Link intentionally built a Chinese government backdoor into its routers.

The legal claims focus instead on security vulnerabilities, privacy disclosures, corporate ties and risks associated with Chinese law.

Some TP-Link routers have been compromised by state-backed hackers in previous campaigns, but those incidents involved exploitation of vulnerabilities or malware deployment rather than evidence of a manufacturer-installed backdoor.

TP-Link Denies the Claims

TP-Link Systems says the coordinated lawsuits are based on false premises and unfairly target an independent U.S. company.

The company states that routers sold in the United States are manufactured in Vietnam and that TP-Link Systems is not owned or controlled by the Chinese government or Chinese Communist Party.

TP-Link also says it does not share customer network data with foreign governments or unauthorized third parties.

Those statements directly dispute several of the allegations raised by the states.

Router Security Claims Are a Major Part of the Cases

The lawsuits also challenge how TP-Link markets the security of its consumer routers.

Some complaints cite language from TP-Link’s HomeShield security service, which has been promoted as providing broad network protection.

The states compare those marketing claims with cases where TP-Link routers were exploited by attackers or reached end of life without receiving further security updates.

Whether those claims amount to deceptive marketing will ultimately be determined through the legal process.

Past Attacks Involving TP-Link Routers

The complaints reference previously documented cyber campaigns in which attackers compromised TP-Link routers.

Microsoft reported in 2024 that a China-linked threat group operated a large network of compromised small-office and home routers used for password-spraying activity.

TP-Link devices made up a large share of that observed botnet, although routers from other manufacturers were also involved.

The FBI has also previously linked Russian military intelligence activity to compromised TP-Link routers affected by known vulnerabilities.

These incidents show that TP-Link routers have been exploited in real attacks, but they do not by themselves establish the broader legal claims made by the states.

Five Aginet Router Vulnerabilities Also Cited

Florida, Montana and Nebraska also cite five vulnerabilities affecting TP-Link Aginet devices supplied by internet service providers.

The flaws were disclosed by TP-Link and later analyzed by SEC Consult.

The most serious issue, CVE-2025-30237, can allow an unauthenticated attacker with network access to the device’s management interface to perform privileged actions.

Researchers said the combined flaws could allow a local-network attacker to gain full control of affected devices under certain conditions.

Key TP-Link Vulnerabilities Cited

CVEImpactTP-Link Severity
CVE-2025-30237Authentication bypass and privileged actionsHigh — 8.7
CVE-2025-30238Privilege escalation through account creationHigh — 8.6
CVE-2025-30239Decryption of stored credentials using hardcoded keysHigh — 8.5
CVE-2025-30240File read through crafted USB linkMedium — 5.1
CVE-2025-30241Command execution with elevated privilegesHigh — 8.6

The flaws affect multiple TP-Link ISP-supplied device families.

TP-Link says firmware updates are distributed through internet service providers, meaning some customers may not be able to download patches directly.

FCC Scrutiny Adds More Pressure

The lawsuits are unfolding while TP-Link is also facing heightened federal scrutiny.

A group of 21 state attorneys general recently sent a letter to the Federal Communications Commission raising concerns about TP-Link’s security claims, manufacturing structure and China-related disclosures.

The letter did not directly demand that the FCC reject TP-Link’s applications for new products, but it urged regulators to address those concerns before granting approvals.

New Foreign-Made Consumer Routers Face FCC Restrictions

The FCC has introduced restrictions affecting new foreign-made consumer routers sold in the United States.

Under the rules, new routers manufactured outside the U.S. require conditional approval before receiving equipment authorization.

TP-Link has said its previously authorized routers remain legal to sell and use while the company pursues approval for future products.

Why the China-Ties Allegation Is Complicated

TP-Link Systems says it separated from its China-based affiliate and became an independent U.S. company.

The lawsuits argue that substantial manufacturing, research and supply-chain relationships with China remain.

For example, Nebraska alleges that a large share of components used in TP-Link’s Vietnam manufacturing operations still originate from or move through China.

TP-Link disputes the idea that those relationships amount to foreign control.

Privacy Concerns Are Also Part of the Lawsuits

The states also raise concerns about data collected through TP-Link applications such as Tether, Tapo, Deco and Kasa Smart.

Those apps may collect information including:

  • Email addresses
  • Location data
  • Device identifiers
  • Phone-related information

The complaints argue that users are not adequately informed about potential risks created by Chinese intelligence laws.

TP-Link rejects the suggestion that it provides customer data to foreign governments.

What the States Want From the Courts

The lawsuits seek different remedies depending on the state.

Florida is asking for a permanent court order, financial recovery and civil penalties for alleged violations.

Montana is also seeking monetary penalties.

Nebraska wants TP-Link to provide clearer disclosures about product origin, supply-chain ties and known vulnerabilities.

The cases remain unresolved, and no court has yet ruled that the allegations are proven.

What TP-Link Users Should Do

The lawsuits themselves do not mean every TP-Link router is unsafe.

Users should focus on practical security steps rather than legal headlines alone.

  • Install the latest firmware available for the router.
  • Check whether the device has reached end of life.
  • Replace unsupported routers that no longer receive updates.
  • Disable remote administration when it is not needed.
  • Use a strong administrator password.
  • Disable unused services.
  • Review DNS settings for unexpected changes.
  • Check with the ISP if the router is provider-managed.

ISP-Supplied TP-Link Devices Require Extra Attention

Customers using ISP-provided Aginet routers may depend on their internet provider for firmware updates.

TP-Link says customized ISP firmware may not be available for public download.

If the router does not show an available update, users should contact their ISP and ask whether the latest fixed firmware has been deployed.

Do These Lawsuits Mean TP-Link Routers Are Banned?

No.

The lawsuits themselves do not ban existing TP-Link routers.

Existing products that already have U.S. equipment authorization can continue to be used and sold under current rules.

The regulatory issue primarily affects approval of new foreign-made consumer router models.

Frequently Asked Questions

Why is TP-Link being sued?

Several U.S. states allege that TP-Link made misleading statements about router security, its relationship with China and privacy risks.

Which states have sued TP-Link?

Florida, Iowa, Montana and Nebraska filed lawsuits in October 2026. Texas filed a separate suit earlier in the year.

Has TP-Link admitted wrongdoing?

No. TP-Link denies the allegations and says the lawsuits are based on false premises.

Did TP-Link install a Chinese government backdoor?

The complaints cited in public reporting do not allege that TP-Link intentionally installed a Chinese government backdoor in its routers.

Have TP-Link routers been hacked before?

Yes. TP-Link devices have been compromised in real-world campaigns involving state-backed hackers, although routers from other vendors have also been targeted.

Are TP-Link routers banned in the United States?

No. Existing authorized models remain legal to sell and use. New foreign-made consumer routers face additional FCC approval requirements.

What should TP-Link users do now?

Keep firmware updated, replace unsupported devices, secure administrator access and check with the ISP if the device is provider-managed.

Final Takeaway

The expanding TP-Link router lawsuit dispute represents a mix of cybersecurity, consumer protection, privacy and geopolitical concerns.

Five U.S. states have now taken legal action, but the allegations remain contested and have not been proven in court.

TP-Link denies that its products give foreign governments unauthorized access and says its U.S. business is independent.

For users, the most practical response is to focus on firmware updates, device support status and secure router configuration rather than assuming that every TP-Link device is compromised.

Stay Updated on Network Security

Routers and other internet-facing devices continue to be attractive targets for state-backed hackers, botnets and credential-stealing campaigns.

Follow CyberUpdates365 for verified network security news, vulnerabil ity alerts, router security updates and practical defense guidance.

Official and Primary Sources

TP-Link Response:
TP-Link Systems response to the state lawsuits

Nebraska Attorney General:
Nebraska lawsuit announcement

Montana Department of Justice:
Montana lawsuit announcement

Uday Patil
About The Author

Uday Patil

Uday Patil is a Cybersecurity Researcher, DevSecOps Engineer, and the Founder of CyberUpdates365. Specializing in Threat Intelligence and Zero-Day vulnerability analysis, Uday is dedicated to breaking down complex cyber threats into actionable insights. His mission is to empower developers, security teams, and aspiring tech talent with rapid alerts, practical guidance, and career mentorship.