TP-Link Faces State Lawsuits Over ISP Router Flaws

www.news4hackers.com-tp-link-faces-state-lawsuits-over-isp-router-flaws-tp-link-faces-state-lawsuits-over-isp-router-flaws

TP-Link is under legal scrutiny from multiple U.S. states over alleged security flaws in its networking equipment, with lawsuits citing misrepresentation and ties to China.

Legal Challenges Against TP-Link

Four U.S. states—Florida, Iowa, Montana, and Nebraska—filed lawsuits on October 6, joining Texas, which had initiated similar action in February. The complaints allege that TP-Link misrepresented the security capabilities of its products and concealed its ties to China, leveraging state-specific consumer protection statutes.

Allegations of Misrepresentation

The states argue that TP-Link’s marketing materials overstated the security features of its HomeShield service, which was advertised as providing “100% safeguard” coverage as recently as November 2025. They reference congressional testimony linking TP-Link routers to cyber operations attributed to Chinese threat groups, including the Volt Typhoon and Flax Typhoon campaigns.

“TP-Link’s devices are being used as a Trojan horse for the Chinese government,” said Montana’s attorney general, urging the FCC to review the company’s compliance with national security standards.

Technical Flaws and Security Concerns

The lawsuits highlight that certain TP-Link models lack automatic firmware updates and no longer receive security patches. They also challenge the company’s claims of separation from China, asserting that significant portions of its research, development, and manufacturing remain in the country. The states note that only 0.5% of components used at TP-Link’s Vietnam facility are sourced locally.

Technical Vulnerabilities Exposed

Security researchers at SEC Consult identified five vulnerabilities in TP-Link’s Aginet line of ISP-managed devices, tracked as CVE-2025-30237 through CVE-2025-30241. These flaws affect routers, modems, and mesh systems, allowing unauthenticated attackers to gain administrative access, perform command injection, and extract sensitive data via hardcoded encryption keys.

Impact and Response

TP-Link disclosed 65 affected devices, with initial fixes completed by January 2025. However, identifying all impacted models took until July 2025, and firmware updates for ISPs were rolled out through 2026. The company advises users to check device management interfaces for updates. SEC Consult withheld proof-of-concept code due to concerns about unpatched devices.

TP-Link’s Denial and Industry Implications

TP-Link has denied the allegations, calling the lawsuits “baseless” and asserting that its U.S.-sold devices are manufactured in Vietnam. The company claims it has provided regulators with documentation to support this. However, Montana’s attorney general joined a coalition of 21 states in urging the FCC to review TP-Link’s compliance with national security standards.

FCC and Supply Chain Security

The FCC is considering adding foreign-manufactured routers to its Covered List, which could impact TP-Link’s ability to sell new models in the U.S. The legal and technical scrutiny underscores broader concerns about supply chain security and the risks posed by networking equipment with unresolved vulnerabilities.

Conclusion

The ongoing legal and technical challenges against TP-Link highlight the critical importance of transparency and security in networking equipment, with implications for both consumers and national security frameworks.



About Author

en_USEnglish