Four US states have sued TP-Link Systems, accusing the router maker of misleading consumers about the security of its products and its ties to China.
The attorneys general of Florida, Iowa, Montana, and Nebraska filed the lawsuits on October 6 in their respective state courts. Each relies on its state’s consumer protection laws. Texas filed a similar lawsuit against the company in February.
The new state complaints, which are nearly identical, argue that TP-Link’s marketing overstates the protection its devices provide. They single out claims that the company’s HomeShield service “covers all security scenarios” and, as recently as November 2025, offered a “100% safeguard.”
To counter those claims, the states cite congressional testimony that TP-Link routers were exploited in the Volt Typhoon and Flax Typhoon campaigns. They also point to botnets used by Chinese threat actors for password spraying attacks, and to Russian hackers targeting TP-Link routers.
According to the complaints, several of the exploited models do not support automatic firmware updates and no longer receive security updates.
The states also take aim at TP-Link’s claimed separation from China. They allege that much of its research, development, and manufacturing remains there, and that only 0.5% of the components used at its Vietnam factory, by value, are bought in Vietnam.
The complaints further claim that TP-Link’s privacy policies do not disclose that its Chinese affiliates are subject to China’s intelligence law. The states also say TP-Link fails to disclose 2021 Chinese regulations that require newly discovered vulnerabilities to be reported to the government.
The complaints seek injunctions, civil penalties, and the return of money obtained through the alleged violations, and request jury trials.
SEC Consult details ISP router flaws named in the complaints
To show that TP-Link’s security problems persist, the complaints cite five vulnerabilities, tracked as CVE-2025-30237 through CVE-2025-30241, that TP-Link disclosed in August. The issues affect the company’s Aginet line of ISP-managed mesh systems, routers, and modems.
On Thursday, SEC Consult, whose researchers discovered the flaws, published technical details.
“These vulnerabilities allowed an unauthenticated attacker on the same network to fully compromise the affected device,” SEC Consult said.
The most severe of the bugs, CVE-2025-30237, is an authentication bypass in the device’s web server. An attacker with access to the web interface could abuse it to create a super-administrator account and enable SSH access, without any credentials.
CVE-2025-30238 allows a low-privileged user to perform actions meant for administrators. CVE-2025-30241 is a command injection issue in the web interface that lets an authenticated attacker run commands with root privileges.
CVE-2025-30239 stems from the use of hardcoded encryption keys, tied only to the device model, to protect configuration files and backups. An attacker who obtains these files and extracts the keys from the firmware can recover user passwords, Wi-Fi credentials, and, depending on the configuration, credentials used for remote management by the ISP.
The fifth issue, CVE-2025-30240, requires physical access. An attacker could plug in a specially prepared USB drive to read the device’s entire file system.
TP-Link identified 65 affected devices, including mesh systems, routers, fiber (PON) devices, and DSL modems. Its advisory notes that ISP-customized variants of these models are also affected.
SEC Consult began reporting the flaws to TP-Link in December 2024. The vendor said in January 2025 that the initial issues were fixed, but identifying all affected models took until July 2025. The rollout of fixes, which included custom firmware for affected ISPs, stretched into 2026.
TP-Link says firmware updates for the affected devices are distributed by ISPs. It advises users to check their device’s management interface or app for updates and to contact their ISP if none are available.
SEC Consult did not release PoC exploit code due to concerns that many vulnerable devices remain unpatched.
TP-Link calls lawsuits ‘baseless’
In an October 6 statement, TP-Link rejected the allegations.
“The coordinated lawsuits are built on false premises. They do nothing to advance national security while unfairly penalizing an industry-leading U.S. company,” said Steve Kovsky, TP-Link’s corporate affairs officer.
The company said it had spent months providing state regulators with documentation showing that its US devices are manufactured in Vietnam and that it is not owned or controlled by any foreign government.
“Any claims that our products present a threat to user security or grant unauthorized network access to foreign governments are baseless,” TP-Link said.
On October 7, Montana Attorney General Austin Knudsen joined a coalition of 21 state attorneys general in a letter urging the FCC to scrutinize TP-Link. The company is seeking conditional approval to sell new router models in the US, after the FCC moved in March to add routers produced in foreign countries to its Covered List.
“TP-Link routers should be considered a Trojan horse planted by the Chinese Communist Party to spy on Americans. I hope the FCC seriously considers TP-Link’s concerning practices and declines to grant the conditional approval they are seeking for the sake of our national security,” Knudsen said.
Related: TP-Link Patches High-Severity Router Vulnerabilities
Related: TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover
Related: Hackers Fail to Exploit Flaw in Discontinued TP-Link Routers


