Four states file suit alleging deceptive security and hidden China ties
The attorneys general of Florida, Iowa, Montana, and Nebraska have filed a complaint accusing California-based TP-Link Systems of misleading marketing about router security and of concealing "past and ongoing ties to the People's Republic of China." The complaint, filed in state court, frames the company's statements about device safety and supply-chain changes as deceptive and unfair business practices. It cites repeated firmware vulnerabilities, a supply chain it says remains reliant on PRC players, and legal obligations under Chinese law that the complaint says could require companies to cooperate with state intelligence.
Specific technical and intelligence claims cited in the complaint
The complaint cites testimony and cyber‑incident reporting to support its security assertions. It points to 2025 testimony from former NSA cybersecurity director Rob Joyce that TP-Link accounted for at least 60 percent of the U.S. retail market for Wi‑Fi systems and small‑office/home‑office (SoHo) routers. The suit also cites assertions that TP‑Link routers were among brands exploited by state‑linked campaigns called Volt Typhoon and Flax Typhoon, and it characterizes the devices' problems as including "critical vulnerabilities" that undermined the marketing claims.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleConflicting market figures and product claims
The complaint draws on marketing materials to argue TP‑Link overstated device security. Lawyers highlighted language from TP‑Link's HomeShield product, including a claim that it "covers all security scenarios" and, on a version of the company's website available in November 2025, a promise of a "100 percent safeguard" for network security. Market figures referenced in public material are inconsistent: data from Circana cited in the report show TP‑Link held roughly 36.6 percent U.S. market share by units and 31 percent by dollars in 2024, while testimony attributed to Rob Joyce places TP‑Link's share at a minimum of 60 percent in the retail Wi‑Fi and SoHo router market.
Supply chain, Vietnam factory, and allegations of Chinese involvement
The states' complaint disputes TP‑Link's claims that it severed ties with China and moved manufacturing to Vietnam. It alleges that only 0.5 percent of components used at TP‑Link's Vietnamese plant, measured by value, are bought in Vietnam, with "all other inputs" imported "from or through China." The filing further asserts that a U.S.‑designated Chinese military company carried out construction work at the Vietnamese factory, a fact the complaint says challenges TP‑Link's assurances about the security and independence of its supply chain.
TP‑Link's corporate affairs officer, Steve Kovsky, responded that the lawsuits rest on "false premises" and "do nothing to advance national security." Kovsky said the company has provided officials with documentation showing it is not owned or controlled by any foreign government and that devices sold in the U.S. are manufactured in Vietnam. "Any claims that our products present a threat to user security or grant unauthorized network access to foreign governments are baseless," he said, adding that the company "does not, and will not, share customer network data with foreign governments or unauthorized third parties" and that it "stands fully behind the security of our products."
Regulatory backdrop and prior litigation
The complaint follows a separate suit brought earlier this year by the Texas attorney general, which raised similar concerns about TP‑Link's Chinese connections and router security. Regulators have also acted: the Federal Communications Commission in March 2026 imposed broader restrictions on new foreign‑produced router models, barring new equipment authorizations unless an exemption is granted, though previously authorized models were not automatically banned.
What this means for technologists, policymakers, and consumers
- Technologists and security teams: The complaint's references to "critical vulnerabilities" and to exploitation by Volt Typhoon and Flax Typhoon mean device inventories and patch programs will be places to focus. The complaint itself cites firmware flaws and specific exploitation narratives as the basis for its deception claims.
- Policymakers and regulators: State attorneys general have escalated enforcement through litigation, while the FCC has already tightened approval rules for new foreign‑produced router models as of March 2026—both moves that could shape procurement and authorization decisions.
- Consumers and procurement officers: The suit draws attention to product marketing claims such as HomeShield's "covers all security scenarios" or a "100 percent safeguard" and to the complaint's allegation that supply‑chain inputs continue to flow from or through China despite manufacturing in Vietnam.
The case lays contested technical and corporate claims before a court while TP‑Link insists it will "refute these baseless allegations in court." With prior litigation from Texas and regulatory steps by the FCC already on the record, the lawsuit by Florida, Iowa, Montana, and Nebraska moves the dispute into another legal forum and underscores the overlap of product security, supply‑chain provenance, and state enforcement.




