Close Menu
NCIJ Network NCIJ Network
    What's Hot

    ‘Vote “yes” for all of us’: Why Cook County judges run as a ‘class’

    October 8, 2026

    American Academy of Pediatrics Calls for Raw Milk Ban — ProPublica

    October 8, 2026

    Free land for those who will build on it. Is this the radical solution to the UK’s social housing problem? | Phineas Harper

    October 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • ‘Vote “yes” for all of us’: Why Cook County judges run as a ‘class’
    • American Academy of Pediatrics Calls for Raw Milk Ban — ProPublica
    • Free land for those who will build on it. Is this the radical solution to the UK’s social housing problem? | Phineas Harper
    • First Thing: Trump endures protests in Texas as DNC sues over adverts | US news
    • Italy overhauls electoral system after fiercely contested debate
    • Asos hackers took more personal details than first revealed, BBC finds
    • NVIDIA PivotOPD Teaches Multi-Turn AI Agents to Recover From Pivotal Mistakes
    • Rein Security Raises $25 Million to Guard AI Agents at Runtime
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 8, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Four US states have sued TP-Link Systems, accusing the router maker of misleading consumers about the security of its products and its ties to China.

    The attorneys general of Florida, Iowa, Montana, and Nebraska filed the lawsuits on October 6 in their respective state courts. Each relies on its state’s consumer protection laws. Texas filed a similar lawsuit against the company in February.

    The new state complaints, which are nearly identical, argue that TP-Link’s marketing overstates the protection its devices provide. They single out claims that the company’s HomeShield service “covers all security scenarios” and, as recently as November 2025, offered a “100% safeguard.”

    To counter those claims, the states cite congressional testimony that TP-Link routers were exploited in the Volt Typhoon and Flax Typhoon campaigns. They also point to botnets used by Chinese threat actors for password spraying attacks, and to Russian hackers targeting TP-Link routers.

    According to the complaints, several of the exploited models do not support automatic firmware updates and no longer receive security updates.

    The states also take aim at TP-Link’s claimed separation from China. They allege that much of its research, development, and manufacturing remains there, and that only 0.5% of the components used at its Vietnam factory, by value, are bought in Vietnam.

    Advertisement. Scroll to continue reading.

    The complaints further claim that TP-Link’s privacy policies do not disclose that its Chinese affiliates are subject to China’s intelligence law. The states also say TP-Link fails to disclose 2021 Chinese regulations that require newly discovered vulnerabilities to be reported to the government.

    The complaints seek injunctions, civil penalties, and the return of money obtained through the alleged violations, and request jury trials.

    SEC Consult details ISP router flaws named in the complaints

    To show that TP-Link’s security problems persist, the complaints cite five vulnerabilities, tracked as CVE-2025-30237 through CVE-2025-30241, that TP-Link disclosed in August. The issues affect the company’s Aginet line of ISP-managed mesh systems, routers, and modems.

    On Thursday, SEC Consult, whose researchers discovered the flaws, published technical details.

    “These vulnerabilities allowed an unauthenticated attacker on the same network to fully compromise the affected device,” SEC Consult said.

    The most severe of the bugs, CVE-2025-30237, is an authentication bypass in the device’s web server. An attacker with access to the web interface could abuse it to create a super-administrator account and enable SSH access, without any credentials.

    CVE-2025-30238 allows a low-privileged user to perform actions meant for administrators. CVE-2025-30241 is a command injection issue in the web interface that lets an authenticated attacker run commands with root privileges.

    CVE-2025-30239 stems from the use of hardcoded encryption keys, tied only to the device model, to protect configuration files and backups. An attacker who obtains these files and extracts the keys from the firmware can recover user passwords, Wi-Fi credentials, and, depending on the configuration, credentials used for remote management by the ISP.

    The fifth issue, CVE-2025-30240, requires physical access. An attacker could plug in a specially prepared USB drive to read the device’s entire file system.

    TP-Link identified 65 affected devices, including mesh systems, routers, fiber (PON) devices, and DSL modems. Its advisory notes that ISP-customized variants of these models are also affected.

    SEC Consult began reporting the flaws to TP-Link in December 2024. The vendor said in January 2025 that the initial issues were fixed, but identifying all affected models took until July 2025. The rollout of fixes, which included custom firmware for affected ISPs, stretched into 2026.

    TP-Link says firmware updates for the affected devices are distributed by ISPs. It advises users to check their device’s management interface or app for updates and to contact their ISP if none are available. 

    SEC Consult did not release PoC exploit code due to concerns that many vulnerable devices remain unpatched.

    TP-Link calls lawsuits ‘baseless’

    In an October 6 statement, TP-Link rejected the allegations.

    “The coordinated lawsuits are built on false premises. They do nothing to advance national security while unfairly penalizing an industry-leading U.S. company,” said Steve Kovsky, TP-Link’s corporate affairs officer.

    The company said it had spent months providing state regulators with documentation showing that its US devices are manufactured in Vietnam and that it is not owned or controlled by any foreign government.

    “Any claims that our products present a threat to user security or grant unauthorized network access to foreign governments are baseless,” TP-Link said.

    On October 7, Montana Attorney General Austin Knudsen joined a coalition of 21 state attorneys general in a letter urging the FCC to scrutinize TP-Link. The company is seeking conditional approval to sell new router models in the US, after the FCC moved in March to add routers produced in foreign countries to its Covered List.

    “TP-Link routers should be considered a Trojan horse planted by the Chinese Communist Party to spy on Americans. I hope the FCC seriously considers TP-Link’s concerning practices and declines to grant the conditional approval they are seeking for the sake of our national security,” Knudsen said.

    Related: TP-Link Patches High-Severity Router Vulnerabilities

    Related: TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover

    Related: Hackers Fail to Exploit Flaw in Discontinued TP-Link Routers

    faces flaws ISP lawsuits Router Scrutiny state TPLink
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Rein Security Raises $25 Million to Guard AI Agents at Runtime

    Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme

    We are fighting phishing at the wrong layer

    FortiBleed Attackers Locking Victims Out of Fortinet Devices

    Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

    Hackers hijack Google domains after breaching ccTLD registries

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    ‘Vote “yes” for all of us’: Why Cook County judges run as a ‘class’

    October 8, 2026

    American Academy of Pediatrics Calls for Raw Milk Ban — ProPublica

    October 8, 2026

    Free land for those who will build on it. Is this the radical solution to the UK’s social housing problem? | Phineas Harper

    October 8, 2026

    First Thing: Trump endures protests in Texas as DNC sues over adverts | US news

    October 8, 2026
    Latest Posts

    British national shot dead in Kashmir by Pakistani security forces | Kashmir

    August 10, 2026

    Climate change doubled likelihood of Canada’s extreme fire weather, study finds

    August 10, 2026

    Scientists say just 7 days of meditation can rewire your brain

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    ‘Vote “yes” for all of us’: Why Cook County judges run as a ‘class’

    October 8, 2026

    American Academy of Pediatrics Calls for Raw Milk Ban — ProPublica

    October 8, 2026

    Free land for those who will build on it. Is this the radical solution to the UK’s social housing problem? | Phineas Harper

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.