TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
TP-Link sued by four US states over alleged security misrepresentations and China ties.
Summary
Four US states, along with Texas, have filed lawsuits against TP-Link, alleging the company misled consumers about the security of its routers and its connections to China. The complaints cite claims of exaggerated security features and point to the exploitation of TP-Link routers in nation-state campaigns like Volt Typhoon. SEC Consult also published technical details on five critical vulnerabilities affecting TP-Link's Aginet line, which allow for full device compromise.
Full text
Four US states have sued TP-Link Systems, accusing the router maker of misleading consumers about the security of its products and its ties to China. The attorneys general of Florida, Iowa, Montana, and Nebraska filed the lawsuits on October 6 in their respective state courts. Each relies on its state’s consumer protection laws. Texas filed a similar lawsuit against the company in February. The new state complaints, which are nearly identical, argue that TP-Link’s marketing overstates the protection its devices provide. They single out claims that the company’s HomeShield service “covers all security scenarios” and, as recently as November 2025, offered a “100% safeguard.” To counter those claims, the states cite congressional testimony that TP-Link routers were exploited in the Volt Typhoon and Flax Typhoon campaigns. They also point to botnets used by Chinese threat actors for password spraying attacks, and to Russian hackers targeting TP-Link routers. According to the complaints, several of the exploited models do not support automatic firmware updates and no longer receive security updates. The states also take aim at TP-Link’s claimed separation from China. They allege that much of its research, development, and manufacturing remains there, and that only 0.5% of the components used at its Vietnam factory, by value, are bought in Vietnam.Advertisement. Scroll to continue reading. The complaints further claim that TP-Link’s privacy policies do not disclose that its Chinese affiliates are subject to China’s intelligence law. The states also say TP-Link fails to disclose 2021 Chinese regulations that require newly discovered vulnerabilities to be reported to the government. The complaints seek injunctions, civil penalties, and the return of money obtained through the alleged violations, and request jury trials. SEC Consult details ISP router flaws named in the complaints To show that TP-Link’s security problems persist, the complaints cite five vulnerabilities, tracked as CVE-2025-30237 through CVE-2025-30241, that TP-Link disclosed in August. The issues affect the company’s Aginet line of ISP-managed mesh systems, routers, and modems. On Thursday, SEC Consult, whose researchers discovered the flaws, published technical details. “These vulnerabilities allowed an unauthenticated attacker on the same network to fully compromise the affected device,” SEC Consult said. The most severe of the bugs, CVE-2025-30237, is an authentication bypass in the device’s web server. An attacker with access to the web interface could abuse it to create a super-administrator account and enable SSH access, without any credentials. CVE-2025-30238 allows a low-privileged user to perform actions meant for administrators. CVE-2025-30241 is a command injection issue in the web interface that lets an authenticated attacker run commands with root privileges. CVE-2025-30239 stems from the use of hardcoded encryption keys, tied only to the device model, to protect configuration files and backups. An attacker who obtains these files and extracts the keys from the firmware can recover user passwords, Wi-Fi credentials, and, depending on the configuration, credentials used for remote management by the ISP. The fifth issue, CVE-2025-30240, requires physical access. An attacker could plug in a specially prepared USB drive to read the device’s entire file system. TP-Link identified 65 affected devices, including mesh systems, routers, fiber (PON) devices, and DSL modems. Its advisory notes that ISP-customized variants of these models are also affected. SEC Consult began reporting the flaws to TP-Link in December 2024. The vendor said in January 2025 that the initial issues were fixed, but identifying all affected models took until July 2025. The rollout of fixes, which included custom firmware for affected ISPs, stretched into 2026. TP-Link says firmware updates for the affected devices are distributed by ISPs. It advises users to check their device’s management interface or app for updates and to contact their ISP if none are available. SEC Consult did not release PoC exploit code due to concerns that many vulnerable devices remain unpatched. TP-Link calls lawsuits ‘baseless’ In an October 6 statement, TP-Link rejected the allegations. “The coordinated lawsuits are built on false premises. They do nothing to advance national security while unfairly penalizing an industry-leading U.S. company,” said Steve Kovsky, TP-Link’s corporate affairs officer. The company said it had spent months providing state regulators with documentation showing that its US devices are manufactured in Vietnam and that it is not owned or controlled by any foreign government. “Any claims that our products present a threat to user security or grant unauthorized network access to foreign governments are baseless,” TP-Link said. On October 7, Montana Attorney General Austin Knudsen joined a coalition of 21 state attorneys general in a letter urging the FCC to scrutinize TP-Link. The company is seeking conditional approval to sell new router models in the US, after the FCC moved in March to add routers produced in foreign countries to its Covered List. “TP-Link routers should be considered a Trojan horse planted by the Chinese Communist Party to spy on Americans. I hope the FCC seriously considers TP-Link’s concerning practices and declines to grant the conditional approval they are seeking for the sake of our national security,” Knudsen said. Related: TP-Link Patches High-Severity Router Vulnerabilities Related: TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover Related: Hackers Fail to Exploit Flaw in Discontinued TP-Link Routers Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Anthropic Introduces 3-Tier Cyber Verification Program for AI AccessWikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into ProxiesFBI Blames Contractor’s Missed Patch for ShinyHunters BreachCybersecurity M&A Roundup: 39 Deals Announced in September 2026Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated ReportsExploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days EarlierCrypto Scammers Hijack Microsoft’s Official X AccountAI Agents Aimed SQL Injection at US and Canadian Government Sites Latest News Rein Security Raises $25 Million to Guard AI Agents at RuntimeFake Decryption Tools Masked $11M Markup in Ransomware Recovery SchemeOracle Health Data Breach Tally Climbs to Nearly 20 MillionFortiBleed Attackers Locking Victims Out of Fortinet DevicesGeorgia Power, Alabama Power Data Breach Hits 400,000 AccountsQilin Ransomware Suspect Arrested in Japan, Extradited to GermanyHadrian Raises $40 Million to Expand Autonomous Offensive Security PlatformAdvantest Discloses Data Breach Months After Ransomware Attack Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveChip Wentz has been appointed as SVP &
Indicators of Compromise
- cve — CVE-2025-30237
- cve — CVE-2025-30238
- cve — CVE-2025-30239
- cve — CVE-2025-30240
- cve — CVE-2025-30241