"The coordinated lawsuits are built on false premises. They do nothing to advance national security while unfairly penalizing an industry‑leading U.S. company," Steve Kovsky, TP‑Link's corporate affairs officer, said the day the latest suits were filed.
The state cases: who sued and what they seek
On October 6, Florida, Iowa, Montana and Nebraska filed consumer‑protection suits against TP‑Link Systems in state courts, bringing the total to five states after Texas filed in February. The complaints allege TP‑Link misled buyers about device security and about how separate TP‑Link Systems is from its former Chinese affiliate. TP‑Link denies the claims and says it will fight them in court.
Florida seeks a permanent court order, disgorgement of profits and $10,000 for each willful violation; Montana asks for up to $10,000 per violation. Nebraska wants court-ordered disclosures telling buyers where products and parts come from, explaining ties to China, and notifying customers of known exploited vulnerabilities. Iowa's announcement is worded more strongly in places: Attorney General Brenna Bird's office said TP‑Link firmware gives the Chinese government access to Iowans' devices and data, while the same release also describes that access as a potential risk.
Three central allegations: security, China ties, and privacy
The complaints group their claims into three themes. First, states say TP‑Link advertised security it did not deliver. They quote TP‑Link's U.S. HomeShield page as saying the service "covers all security scenarios" — language the suits set against hacked devices and models TP‑Link no longer updates, including two versions of the Archer AX21 that TP‑Link lists as having reached end of life in May 2024.
Second, the suits allege TP‑Link overstated its separation from China. They quote the company saying its 2024 restructuring left it with "entirely different ownership, management, and operations" from TP‑Link Technologies. The complaints cite an April 2025 Bloomberg News report that TP‑Link and TP‑Link Technologies together employed about 11,000 people in China. The suits also note TP‑Link says U.S.‑market routers are made in Vietnam, while alleging only 0.5% of parts by value at the Vietnamese factory are sourced in Vietnam and the rest are sourced from or through China.
Third, states press privacy concerns. The complaints say TP‑Link's Tether, Tapo, Deco and Kasa Smart apps collect email addresses, location and phone identifiers and note a 2017 Chinese intelligence law could expose such data to Chinese intelligence agencies.

Your scanner finds 4,000 vulns. Which 12 matter?
Nubivance is a Rapid7 Registered Partner delivering vulnerability management as a service - scanning, risk-based prioritization, and remediation follow-through across IT and OT.
Fix the backlogAttacks and public findings cited by the complaints
The complaints point to multiple, documented incidents in which TP‑Link routers were exploited. Microsoft reported in 2024 that a hacking group it believes is in China had built a network of hacked small‑office and home routers used for password‑spray attacks, and said TP‑Link routers "make up most of this network," counting an average of 8,000 hacked devices active at any time. The FBI said in April that Russian military intelligence hackers had compromised TP‑Link routers through CVE‑2023‑50224, changing DNS settings and collecting passwords and login tokens. TP‑Link said in May that, with one exception, the products affected by that flaw had reached end of life.
None of the three complaints accuses TP‑Link of planting a backdoor. They cite Check Point Research saying the Horse Shell backdoor was placed on TP‑Link routers by a Chinese state‑backed hacking group. The complaints also reference testimony given in 2025 by Rob Joyce saying TP‑Link routers "were among the various brands" exploited in the Volt Typhoon and Flax Typhoon campaigns; his written testimony cites no source, and TP‑Link disputed the testimony.
Aginet ISP devices, CVE‑2025‑30237, and patching realities
Florida, Montana and Nebraska cite five flaws in TP‑Link's Aginet line of ISP‑supplied mesh systems, routers and modems. TP‑Link disclosed the flaws on August 10; technical details were published by SEC Consult on October 8. SEC Consult described the set as allowing "an unauthenticated attacker on the same network to fully compromise the affected device" and said the main flaw, CVE‑2025‑30237, lets crafted web requests bypass the login check so an attacker can create a "Superadmin" user and enable SSH remote access.
TP‑Link lists 65 affected models across multiple series; only 27 models are listed for all five flaws, according to TP‑Link's CVE records. Many ISP‑customized versions are affected but not listed. SEC Consult reported the flaws to TP‑Link in December 2024; TP‑Link's advisory followed nearly 20 months later and most fixed firmware had been released by February 2026, per SEC Consult's timeline. Updates reach end users through their ISPs, and TP‑Link warns firmware for ISP versions "may not be publicly available for direct download."
Neither advisory reports attacks exploiting these flaws, SEC Consult left exploit commands out of its advisory, and none of the five was in CISA's catalog of known exploited vulnerabilities as of October 8.
What this means for ISPs, regulators, and consumers
- ISPs: are the distribution point for fixes — customers may need to rely on their provider to receive patched firmware because ISP versions "may not be publicly available for direct download."
- Regulators and the FCC: face overlapping tracks — 21 state attorneys general, led by Nebraska Attorney General Mike Hilgers, sent a letter to the FCC raising concerns about TP‑Link's security claims, China ties and privacy disclosures as the company seeks Conditional Approval for new foreign‑made routers; the letter offers to work with the FCC but does not ask the agency to deny or delay approval.
- Consumers: should check a device's management interface or app for firmware updates and contact their ISP if none is offered, per TP‑Link's advisory; they also face differing remedies sought by states, including disclosure obligations and statutory penalties if the suits succeed.
TP‑Link says its existing routers "remain fully authorized" and that it "does not, and will not, share customer network data with foreign governments or unauthorized third parties." The company has vowed to contest the suits. The dispute will play out across state court dockets, in letters to the FCC over Conditional Approval, and in the practical conveyor belt of ISP patch rolls — leaving consumers and regulators watching for how quickly updates reach affected devices and how courts and the FCC weigh the states' three central claims.




