Florida, Iowa, Montana and Nebraska sue TP-Link Systems for security and source of routers

Author: Published 6 min de lectura 0 reading

The images in this article were generated with artificial intelligence. How we publish

On October 6, four State Attorney General filed complaints against TP- Link Systems in U.S. state courts - in addition to a previous Texas lawsuit - for business practices related to the security and provenance of its routers. The demands, filed by Florida, Iowa, Montana and Nebraska, accuse the subsidiary based in Irvine, California of announcing protection that it does not comply with, of distorting independence from its former Chinese matrix and of hiding risks related to data collection. TP-Link denies the charges and has announced that it will refute them in court.

Facts confirmed: the demands exist and are based on public claims of TP-Link about its HomeShield service, on the situation of end-of-life models (EOL) - for example, two versions of the Archer AX21 - and on technical vulnerabilities publicly disseminated by researchers (including the one grouped as CVE-2025-30237 and others discovered by SEC Consult). TP-Link Systems was part of a restructuring in 2024 that the company describes as separation of TP-Link Technologies in China; the Chinese matrix does not appear as demanded in these cases. It is also public that the list of the U.S. Department of Defense. UU includes TP-Link Technologies as an entity linked to the Chinese military apparatus; TP-Link Systems is not on that list. Since March, the Federal Communications Commission (FCC) has imposed a restriction on the authorisation of new routers manufactured outside the US. In addition, there is an exemption that allows previously authorized equipment to continue to receive updates until at least March 2027.

Florida, Iowa, Montana and Nebraska sue TP-Link Systems for security and source of routers
Image generated with IA.

What are the claims (central claims): first, that TP-Link advertised security guarantees (for example, that HomeShield "covers all security scenarios") that were not fulfilled when devices were left without patches or were violated. Second, that the company exaggerated its separation from the Chinese entity and the location of the production chain - TP-Link maintains that the equipment for the US. The US is manufactured in Vietnam, but demands indicate that almost all parts are obtained from or through China -. Third, that their privacy policies and apps collect data that, according to reports, could be subject to requests by Chinese agencies under the 2017 intelligence legislation.

Central technical aspect and real risk: The above-mentioned technical vulnerabilities allow, according to the researchers' reports, an attacker who already has access to the same local network to reach the router's web interface, evades log-in verification, creates a "Superadmin" user and active remote access (SSH), thus obtaining root privileges. This is equivalent to total control of the equipment and allows to change critical configurations such as DNS servers or capture tokens and credentials. The researchers describe the chain of exploitation as critical; however, the requirement of access to the same network segment means that the attacker must first be within the local network - or be able to reach the router interface from the Internet, which is not clear in all cases and that the published communications have not generally confirmed.

Connection with cyber-espionage campaigns and previous cases: There are public incidents in which domestic routers and SOHO were used as a platform for malicious activities: Microsoft noted in 2024 the existence of a network of committed routers used for "password spraying" attacks, with TP-Link among the brands most present in that set; the FBI reported in April the use of CVE-2023-50224 by which Russian intelligence actors committed routers and manipulated DNS to collect credentials. The demands refer to these precedents, and also cite findings of security signatures that attribute backdoors injected by state-sponsored groups. However, There is no charge in the claims that TP-Link has implemented deliberate back doors.

Which parts are affected and how it could result in real impact: domestic users with TP-Link routers, Internet Service Providers (ISP) customers receiving ISP-managed equipment, small offices and ISPs infrastructure that distribute these equipment. The declared EOL models stop receiving official patches, which increases the exposure window. When ISPs personalize firmware and manage updates from their end, end-users may not have a direct way to apply corrections; this complicates rapid mitigation for people without supplier technical support.

uncertain or estimated parts: the demands suggest that Chinese law could force the transfer of data to State agencies, which is a plausible legal risk, but the complaints do not present public evidence that the Chinese government has actually access to data from TP-Link customers. The direct connection between the specific technical vulnerabilities reported by SEC Consult and the intrusions attributed to state campaigns is not demonstrated in public documents: there are coincidences of vectors and background, but there are no public traces that indisputably link these failures to specific espionage events.

Legal and market consequences: the demands seek precautionary measures, compensation and orders that force TP-Link to report with transparency on the origin of parts, business relationships and exploited vulnerabilities. If they succeed, they could force changes in labelling, increased disclosure requirements and fines, and increase regulatory scrutiny of manufacturers whose components come from chains with concentration in China. At the practical level, this can accelerate the preference of ISPs and buyers by equipment of manufacturers that meet "trusted supply chain" criteria or by devices with independent ISP update.

Florida, Iowa, Montana and Nebraska sue TP-Link Systems for security and source of routers
Image generated with IA.

What users should do now (concrete and prioritized actions): review the router firmware status as soon as possible: open the manufacturer's app (ether, Deco, Kasa, Tapo) or the device's web interface and search for updates; if your computer was provided by the ISP and does not see updates, contact the ISP. Change the administration password to a single, robust sentence, and disable remote access (remote / SSH) if you do not need it. Secure IoT devices and sensitive equipment in separate networks (VLAN or guest network) and activate modern Wi-Fi encryption (WPA2 / WPA3). Check the DNS configuration and check records of unusual connections; if you detect unauthorized DNS changes, restore the configuration and update the firmware. Consider replacing models that are already EOL with hardware that receives active support. Finally, enable the registration and monitoring of router activity and keep an updated antivirus / EDR in final equipment.

For those who wish to follow the regulation and official notices: see the manufacturer's safety pages and the FCC's equipment authorisation section for the status of approvals and exemptions. TP-Link - Advisory & Security and FCC - Equipment Authorization are useful starting points for official verifications and updates on new model authorization.

In short, the demands pose a combination of reputational, legal and technical risks that could redesign how regulators and consumers assess network hardware confidence. There are real and exploitable technical failures and there is evidence of routers engaged in malicious campaigns; what is missing for now are conclusive public evidence of direct cooperation between TP-Link Systems and state actors to obtain data from users. As the judicial dispute progresses, the practical measure for most users is simple: check updates, limit remote administrative access, segment the network and replace unsupported equipment.

Coverage

Related

More news on the same subject.