TP-Link sued by four US states over router security claims
Florida, Iowa, Montana and Nebraska have filed lawsuits against TP-Link Systems, claiming the router maker misled consumers about how secure its devices are and how closely it is tied to China.
The attorneys general of the four states filed the complaints on October 6 in their own state courts, each under local consumer protection law. Texas brought a similar case against the company in February.
Marketing claims under fire
The complaints are almost identical. They argue that TP-Link oversells the protection its products offer. They point to claims that the HomeShield service "covers all security scenarios" and that, as late as November 2025, it provided a "100% safeguard."
The states cite congressional testimony that TP-Link routers were abused in the Volt Typhoon and Flax Typhoon campaigns. They also mention botnets that Chinese threat actors used for password spraying, and Russian hackers who went after TP-Link routers. Several of the exploited models do not support automatic firmware updates and no longer get security fixes, according to the filings.
The states also dispute TP-Link's claimed separation from China. They allege that much of its research, development and manufacturing still happens there. They also allege that only 0.5% of the components used at its factory in Vietnam, measured by value, are sourced in Vietnam.
The privacy policies are criticized too. The states say TP-Link does not tell users that its Chinese affiliates are subject to China's intelligence law. It also does not mention 2021 Chinese rules that require newly found vulnerabilities to be reported to the government.
The states want injunctions, civil penalties and the return of money gained through the alleged violations. They have asked for jury trials.
Five flaws in ISP-managed devices
To show that the security problems continue, the complaints refer to five vulnerabilities, CVE-2025-30237 through CVE-2025-30241, which TP-Link disclosed in August. They affect the Aginet line of mesh systems, routers and modems that internet service providers (ISPs) deploy and manage for customers.
SEC Consult, whose researchers found the bugs, published technical details on Thursday. "These vulnerabilities allowed an unauthenticated attacker on the same network to fully compromise the affected device," the firm said.
The most serious one, CVE-2025-30237, is an authentication bypass in the web server. Someone with access to the web interface could create a super-administrator account and turn on SSH without any credentials. CVE-2025-30238 lets a low-privileged user carry out admin actions. CVE-2025-30241 is a command injection flaw that gives an authenticated attacker root-level command execution.
CVE-2025-30239 comes from hardcoded encryption keys, tied only to the device model, that protect configuration files and backups. An attacker who gets these files and pulls the keys from the firmware can recover user passwords and Wi-Fi credentials. Depending on the setup, ISP remote management credentials may be exposed as well. The fifth bug, CVE-2025-30240, needs physical access. A crafted USB drive can be used to read the whole file system.
TP-Link lists 65 affected devices, including mesh systems, routers, fiber (PON) devices and DSL modems, plus ISP-customized variants. SEC Consult started reporting the issues in December 2024. TP-Link said the first ones were fixed in January 2025, but it took until July 2025 to identify every affected model, and fixes, including custom firmware for ISPs, rolled out into 2026. Updates are pushed by ISPs. Users should check the management interface or app and contact their provider if nothing is available. SEC Consult held back proof-of-concept code because many devices are likely still unpatched.
TP-Link pushes back
TP-Link called the cases "built on false premises." Corporate affairs officer Steve Kovsky said they "do nothing to advance national security." The company says it gave regulators documents showing its US devices are made in Vietnam and that no foreign government owns or controls it.
On October 7, Montana Attorney General Austin Knudsen joined 21 state attorneys general urging the FCC, the US communications regulator, to scrutinize TP-Link. The company wants conditional approval to sell new router models after the FCC moved in March to add foreign-made routers to its Covered List. Knudsen called the routers "a Trojan horse planted by the Chinese Communist Party."
Our Take
The lawsuits mix two separate questions: who controls TP-Link, and whether its devices are secure. The second is the one that affects users most directly. The Aginet case shows a familiar problem with ISP-managed hardware. Patches depend on the provider, and the fix cycle here took well over a year. Combined with end-of-life models that no longer get updates, this suggests many homes run routers nobody is actively maintaining.
Network edge devices remain a favorite entry point, as seen in the recent compromise of Fortinet devices. It is worth watching whether the FCC grants TP-Link's conditional approval and whether more states join the litigation. For now, users of ISP-supplied gear should check whether their firmware has been updated.
