Close Menu
NCIJ Network NCIJ Network
    What's Hot

    NASA Seeks US Industry Plans for Commercial Space Stations

    October 9, 2026

    Painted wind turbines can dramatically reduce bird deaths, study finds

    October 9, 2026

    The Guardian view on the 90s revival: the end of the analogue age | Editorial

    October 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • NASA Seeks US Industry Plans for Commercial Space Stations
    • Painted wind turbines can dramatically reduce bird deaths, study finds
    • The Guardian view on the 90s revival: the end of the analogue age | Editorial
    • Pretty Little Liars’ Keegan Allen attacked by masked assailants in LA | Los Angeles
    • Russian search engine Yandex struggles after Ukrainian strikes on data centres
    • Ed Davey faces growing revolt against leadership as senior Lib Dem MP quits | Ed Davey
    • Labour hails byelection win as return of leftwing voters after Starmer era | Holborn and St Pancras byelection
    • Ohio blogger found guilty of harassment for sending Shrek nude to senator
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    TP-Link Sued by Four More U.S. States Over Router Security and China Ties

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 9, 2026 Cybersecurity No Comments9 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link denies the claims and says it will fight them in court.

    TP-Link Systems is based in Irvine, California. Until a 2024 restructuring, it was affiliated with TP-Link Technologies, a Chinese company that the suits do not name as a defendant.

    The complaints from Florida, Montana , and Nebraska do not allege that the Chinese government has obtained customers’ data through TP-Link. They describe that as a risk under Chinese law. Separately, they say state-backed hackers have exploited flaws in TP-Link routers.

    Iowa’s announcement is worded more strongly in places. Attorney General Brenna Bird’s office said TP-Link firmware gives the Chinese government access to Iowans’ devices and data. The same release also describes that access as something that could happen.

    The next day, 21 state attorneys general sent a letter to the Federal Communications Commission (FCC) about TP-Link’s effort to win approval for new router models in the U.S.

    Three of the complaints also cite five flaws in TP-Link devices supplied by internet service providers (ISPs) to customers. Researchers published technical details of those flaws on October 8. Fixes exist, and they reach users through their ISP.

    What The States Allege

    The suits were filed in state courts under consumer-protection laws. The Florida, Montana, and Nebraska complaints share section headings and passages and make the same main claims.

    The first is that TP-Link advertised security it did not deliver. The complaints quote TP-Link’s web page for HomeShield, its built-in network protection service, as saying it “covers all security scenarios.” The U.S. HomeShield page still said so on October 9.

    Cybersecurity

    The complaints set that against routers that were hacked and models that no longer get fixes. One example is two versions of the Archer AX21. TP-Link no longer updates them and says they reached end of life in May 2024, according to the complaints.

    The second claim is that TP-Link overstated its split from China. The complaints quote the company as saying that the restructuring left it with “entirely different ownership, management, and operations” from those of TP-Link Technologies.

    TP-Link and TP-Link Technologies together employed about 11,000 people in China, according to an April 2025 Bloomberg News report the states cite.

    TP-Link says routers for the U.S. market are made in Vietnam. Only 0.5% of the parts used at its Vietnamese factory, by value, are sourced in Vietnam, and the rest are sourced from or through China, according to the complaints.

    The third claim is that TP-Link’s privacy policies leave out a risk. Its Tether, Tapo, Deco and Kasa Smart apps collect email addresses, location and phone identifiers. A 2017 Chinese intelligence law could expose that data to Chinese intelligence agencies, according to the complaints.

    Florida wants a permanent court order against the practices, the surrender of money made from them, and $10,000 for each willful violation. Montana seeks up to $10,000 per violation.

    Nebraska also wants TP-Link ordered to tell buyers where its products and parts come from, about its ties to China, and about known vulnerabilities that have been exploited in its devices.

    TP-Link’s Response

    “The coordinated lawsuits are built on false premises. They do nothing to advance national security while unfairly penalizing an industry-leading U.S. company,” Steve Kovsky, the company’s corporate affairs officer, said in a statement issued the day the suits were filed.

    For months, the statement said, TP-Link has given state regulators documents showing that its U.S. devices are made in Vietnam. It described itself as “an independent, U.S. company that is not owned or controlled by any foreign government.”

    “We do not, and will not, share customer network data with foreign governments or unauthorized third parties,” it said.

    What The Cited Attacks Show

    The complaints point to real attacks in which hackers took over TP-Link routers.

    Microsoft reported in 2024 that a hacking group it believes is in China had built a network of hacked small-office and home routers. The network was used for password-spray attacks, which try common passwords across many accounts.

    TP-Link routers “make up most of this network,” Microsoft said, counting an average of 8,000 hacked devices active at any time.

    The complaints themselves say devices from other brands were hacked as part of the same network.

    The FBI said in April that Russian military intelligence hackers had compromised TP-Link routers through a flaw tracked as CVE-2023-50224. They changed the routers’ DNS settings and collected passwords and login tokens. TP-Link said in May that, with one exception, the products affected by that flaw had reached end of life.

    The claim that Chinese state hackers used TP-Link routers in the Volt Typhoon and Flax Typhoon campaigns rests on testimony given in 2025. Rob Joyce, a former National Security Agency cybersecurity director, told a House committee that TP-Link routers “were among the various brands” exploited. His written testimony cites no source for that.

    TP-Link disputed the testimony the same day, saying those campaigns “have no discernible preference for using TP-Link routers as a vector.”

    None of the three complaints says TP-Link built a backdoor into its products. The one backdoor they name, Horse Shell, was placed on TP-Link routers by a Chinese state-backed hacking group, according to Check Point Research, which the complaints cite.

    The complaints also note that the U.S. Department of Defense in June listed TP-Link Technologies as a Chinese military company. That is the Chinese firm. TP-Link Systems, the company being sued, is not on the list.

    The FCC Letter

    Since March 23, the FCC has barred new foreign-made consumer routers from the equipment authorization they need before they can be sold in the United States. The only exception is a router that wins a “Conditional Approval.”

    Those approvals are decided by the Department of Homeland Security or the Department of Defense, which the FCC’s notice calls the Department of War.

    The rule covers routers made in any foreign country, whatever the maker’s nationality. It applies by place of production, not by company.

    Routers authorized before the rule can continue to receive software and firmware updates “that mitigate harm to U.S. consumers” until at least March 1, 2027, under an FCC waiver.

    TP-Link said in April that its existing routers “remain fully authorized” and that it was “actively pursuing Conditional Approval for new products.”

    The letter, led by Nebraska Attorney General Mike Hilgers and signed by 20 others, raises three concerns with the FCC. They are TP-Link’s security claims, its claims about separating from China and building routers in Vietnam, and what its privacy disclosures leave out about Chinese intelligence law.

    The letter offers to work with the FCC. It does not ask the agency to deny, delay, or attach conditions to an approval.

    “Consumers should be aware of these risks and the FCC should address them before authorizing these new routers for sale in U.S. markets,” Hilgers said in announcing the letter.

    Montana Attorney General Austin Knudsen said he hoped the FCC would refuse the approval.

    Flaws In ISP-Supplied Devices

    Aginet is TP-Link’s line of mesh systems, routers, and modems that ISPs install for customers and keep up to date.

    The complaints from Florida, Montana, and Nebraska cite five flaws in those devices as evidence that TP-Link’s security problems persist. TP-Link disclosed the flaws on August 10. On October 8, the SEC Consult researchers who found them published the technical details.

    Together, the flaws “allowed an unauthenticated attacker on the same network to fully compromise the affected device,” SEC Consult said, and to run commands as root, the highest privilege level.

    Cybersecurity

    The attacker must first be able to reach the device’s web management interface. Neither SEC Consult nor TP-Link says whether that interface can be reached from the internet.

    The main flaw, CVE-2025-30237, allows crafted web requests to bypass the login check. With it, an attacker without an account can create a “Superadmin” user and enable SSH remote access, according to SEC Consult.

    CVE What It Allows What An Attacker Needs TP-Link Rating (CVSS 4.0, Out Of 10) Models Listed, Of 65
    CVE-2025-30237 Privileged actions on the web interface without logging in Network access to the web management interface 8.7, High 56
    CVE-2025-30238 A low-privileged account can create a high-privileged account and enable SSH A valid low-privileged login 8.6, High 59
    CVE-2025-30239 Stored passwords can be decrypted because the keys are hardcoded per model. On some setups this includes the ISP’s remote-management credentials Access to the device’s stored configuration 8.5, High 65
    CVE-2025-30240 Files on the device can be read through a crafted link on a USB stick Physical access to the USB port 5.1, Medium 33
    CVE-2025-30241 Operating-system commands run with elevated privileges A login to the web interface 8.6, High 31

    SEC Consult calls the set of flaws critical.

    TP-Link lists 65 affected models in its HB, HX, and HC mesh series, its EB, EC, and EX router series, its XC and XX fiber devices, and its VX DSL modems. Only 27 of them are listed for all five flaws, according to the CVE records TP-Link published. Versions that ISPs have customized are also affected, and TP-Link does not list those.

    Owners may not be able to download the fix themselves. The updates are delivered through each ISP, and firmware for ISP versions “may not be publicly available for direct download,” TP-Link’s advisory says.

    TP-Link advises users to check the device’s management interface or its app for a firmware update. If none is offered, they should contact their ISP.

    SEC Consult lists no workaround. Neither advisory says how many devices have received the fix.

    SEC Consult reported the flaws to TP-Link in December 2024, and TP-Link’s advisory followed nearly 20 months later. Most of the fixed firmware had been released by February 2026, according to SEC Consult’s timeline.

    SEC Consult left the exploit commands out of its advisory. Neither advisory reports attacks that use the flaws. None of the five was in the U.S. Cybersecurity and Infrastructure Security Agency’s catalog of known exploited vulnerabilities as of its October 8 release.

    Neither the complaints nor the advisories tie these flaws to the attacks described above, or to the allegations about China.

    China Router Security states sued ties TPLink U.S
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

    China Is Reading Arnold Toynbee’s Ideas of a Declining West

    EU and China clinch deal to curb hybrid car exports – POLITICO

    What We Missed: FBI Strikes Back at ShinyHunters

    P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

    Germany arrests alleged core Qilin ransomware member after extradition

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    NASA Seeks US Industry Plans for Commercial Space Stations

    October 9, 2026

    Painted wind turbines can dramatically reduce bird deaths, study finds

    October 9, 2026

    The Guardian view on the 90s revival: the end of the analogue age | Editorial

    October 9, 2026

    Pretty Little Liars’ Keegan Allen attacked by masked assailants in LA | Los Angeles

    October 9, 2026
    Latest Posts

    Reform donor Arron Banks urged to set out extent of surveillance of journalists | Arron Banks

    August 10, 2026

    The Canadian Secessionists Who Love Trump

    August 10, 2026

    How ‘Harry Potter’ Fans Protected Dobby’s Grave From the Path of a U.K.-Ireland Power Line

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    NASA Seeks US Industry Plans for Commercial Space Stations

    October 9, 2026

    Painted wind turbines can dramatically reduce bird deaths, study finds

    October 9, 2026

    The Guardian view on the 90s revival: the end of the analogue age | Editorial

    October 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.