Back to Newsroom
Threat Intel

TP-Link Faces Five U.S. State Lawsuits Over Router Security and China Links

Florida, Iowa, Montana and Nebraska have joined Texas in suing TP-Link over its security and China claims. Five newly detailed Aginet flaws are the part defenders can act on now.

TP-Link Faces Five U.S. State Lawsuits Over Router Security and China Links

TP-Link Faces Five U.S. State Lawsuits Over Router Security and China Links

Four more U.S. states have taken TP-Link Systems to court. That brings the number of state lawsuits against the router maker to five. On October 6, 2026, Florida, Iowa, Montana and Nebraska filed consumer-protection suits. Texas filed the first one in February. The states argue that the Irvine, California-based company misled buyers about how secure its routers are and how independent it is from China. TP-Link rejects the allegations and says it will fight them in court.

At the same time, 21 state attorneys general wrote to the U.S. Federal Communications Commission (FCC) about TP-Link's applications to sell new router models in the United States.

What the states allege

The Florida, Montana and Nebraska complaints follow almost the same outline and make three central claims:

  • Security marketing that doesn't hold up. The states contrast TP-Link's promotion of its HomeShield protection service, which it describes as covering "all security scenarios", with routers that were hacked in the wild and models that stopped receiving updates. One example is two Archer AX21 versions that, according to the complaints, reached end of life in May 2024.
  • An overstated split from China. In a 2024 restructuring, TP-Link Systems separated from the Chinese firm TP-Link Technologies, which is not a defendant. The states say the separation was smaller than advertised. They point to a reported workforce of about 11,000 people in China and a supply chain where nearly all component value for the company's Vietnam-assembled routers comes from or through China.
  • Privacy disclosures that leave out a risk. The companion apps (Tether, Tapo, Deco, Kasa Smart) collect emails, location and device identifiers. The states argue that customers were never told that a 2017 Chinese intelligence law could expose this data.

What the suits do not claim: The three complaints do not say the Chinese government has actually obtained customer data through TP-Link. They also do not say TP-Link planted a backdoor. The only backdoor they mention, "Horse Shell", was implanted on TP-Link firmware by a state-backed threat group, according to Check Point Research. Iowa's announcement goes further and says the firmware gives Beijing access to residents' devices, but elsewhere it describes that access as a possibility. Florida and Montana are seeking penalties of up to $10,000 per violation. Nebraska also wants mandatory disclosure of where products and parts come from and of known exploited vulnerabilities.

TP-Link calls the lawsuits "built on false premises". It says it is an independent U.S. company, that its U.S. devices are made in Vietnam, and that it does not share customer network data with foreign governments.

The attacks behind the headlines

The complaints rely on documented campaigns in which consumer routers were hijacked:

  • In 2024, Microsoft reported that a China-linked password-spray botnet was made up mostly of compromised TP-Link routers, with around 8,000 active at any given time. Other brands were also part of that botnet.
  • The FBI said Russian military intelligence abused CVE-2023-50224 in TP-Link routers to change DNS settings and collect credentials and tokens. TP-Link says nearly all affected models had already reached end of life.
  • The claim that TP-Link routers were used in Volt Typhoon and Flax Typhoon operations comes from 2025 congressional testimony that cited no source. TP-Link disputes it.

On the separate FCC issue: since March 23, 2026, new foreign-made consumer routers can't get U.S. equipment authorization without a "Conditional Approval". The rule applies to the country of manufacture, not to the vendor's nationality. Routers that were already authorized can keep receiving security updates until at least March 1, 2027.

The part defenders should act on: five Aginet flaws

The most practical part of this story is five vulnerabilities in TP-Link's Aginet line. These are the mesh systems, routers and modems that ISPs install and manage for their customers. SEC Consult reported the flaws in December 2024. TP-Link published its advisory in August 2026, and the researchers released technical details on October 8.

CVEImpactPrerequisiteCVSS 4.0
CVE-2025-30237Authentication bypass on the web interface (create "Superadmin", enable SSH)Network access to the management interface8.7 High
CVE-2025-30238Low-privileged user can create a high-privileged account and enable SSHValid low-privilege login8.6 High
CVE-2025-30239Stored passwords decryptable via per-model hardcoded keys, sometimes including ISP remote-management credentialsAccess to device configuration8.5 High
CVE-2025-30240File read through a crafted link on a USB drivePhysical USB access5.1 Medium
CVE-2025-30241OS command execution with elevated privilegesAuthenticated web login8.6 High

SEC Consult says that, chained together, the flaws let an unauthenticated attacker on the same network take full root control of the device. TP-Link lists 65 affected models across its HB/HX/HC mesh, EB/EC/EX router, XC/XX fiber and VX DSL lines. ISP-customized versions are affected too but are not listed.

Keep the risk in proportion: No public exploitation has been reported. None of the five CVEs was in CISA's Known Exploited Vulnerabilities catalog as of October 8. Neither advisory says whether the management interface is reachable from the internet. Neither the lawsuits nor the advisories link these flaws to the attacks or to the China allegations described above.

What to do

  1. Inventory ISP-supplied equipment. Find any TP-Link Aginet device (HB, HX, HC, EB, EC, EX, XC, XX, VX series) in offices, branch sites and remote workers' homes.
  2. Check the firmware, then ask your ISP. Look in the device's management interface or app for an update. Aginet firmware is delivered through the ISP and may not be available for direct download. If no update is offered, open a ticket with your provider and ask for the patched version in writing.
  3. Restrict the management interface. No vendor workaround exists. Make sure the web admin and SSH are not exposed to the WAN, and separate guest and IoT devices from the LAN segment that can reach the router.
  4. Treat stored credentials as exposed. If an affected device has been on an untrusted network, rotate its admin password and any credentials saved on it.
  5. Retire end-of-life routers. Models that no longer get updates, such as older Archer AX21 versions, are the ones attackers actually abuse. Replace them.
  6. Watch DNS settings. Unexpected changes to a router's DNS settings are a known sign of compromise. Check them regularly.
  7. Test from the outside. An external attack-surface assessment will show whether any router admin panel or remote-management service on your perimeter is reachable from the internet.

Originally reported by The Hacker News. This article summarizes and analyzes that coverage.

SHARE