News · Science & Technology
TP-Link Sued by Four More U.S. States Over Router Security and China Ties
Five U.S. states have brought consumer-protection lawsuits against TP-Link Systems, a router maker based in Irvine, California. Florida, Iowa, Montana, Nebraska, and Texas are involved. Four states filed on October 6, while Texas filed in February. The cases matter because they challenge both TP-Link’s security marketing and its statements about separation from China. The complaints allege that TP-Link promoted HomeShield as covering “all security scenarios,” even though some routers were hacked and some models stopped receiving updates. They also challenge claims that a 2024 restructuring created entirely different ownership, management, and operations from Chinese affiliate TP-Link Technologies. The suits do not name that Chinese company as a defendant. TP-Link denies the allegations and says it will fight in court. The states seek different remedies, including court orders, money from the challenged practices, penalties, and disclosures about products, parts, Chinese ties, and exploited vulnerabilities. The cases remain allegations, not findings that TP-Link violated the law.
Based on reporting by The Hacker News
What happened in the lawsuits against TP-Link, and which five U.S. states filed them?
Five U.S. states have brought consumer-protection lawsuits against TP-Link Systems, a router maker based in Irvine, California. Florida, Iowa, Montana, Nebraska, and Texas are involved. Four states filed on October 6, while Texas filed in February. The cases matter because they challenge both TP-Link’s security marketing and its statements about separation from China.
The complaints allege that TP-Link promoted HomeShield as covering “all security scenarios,” even though some routers were hacked and some models stopped receiving updates. They also challenge claims that a 2024 restructuring created entirely different ownership, management, and operations from Chinese affiliate TP-Link Technologies. The suits do not name that Chinese company as a defendant.
TP-Link denies the allegations and says it will fight in court. The states seek different remedies, including court orders, money from the challenged practices, penalties, and disclosures about products, parts, Chinese ties, and exploited vulnerabilities. The cases remain allegations, not findings that TP-Link violated the law.
What is router firmware, and why can a flaw in it put a customer's devices or data at risk?
Router firmware is the built-in software that tells a router how to operate. It manages connections between a home network and the internet, including settings, traffic handling, and security controls. Because it runs at the network’s central gateway, a firmware flaw can affect many connected devices at once.
Attackers may exploit such a flaw to take control of the router or alter how it handles traffic. The article describes Russian military intelligence hackers using CVE-2023-50224 to change DNS settings and collect passwords and login tokens. DNS changes can send users toward attacker-controlled destinations instead of legitimate services. A compromised router can also become part of a larger attack network.
Security updates are therefore important. The article says three complaints cite five flaws in TP-Link devices supplied by internet providers. Researchers published technical details on October 8, and fixes exist. Users receive those fixes through their ISP, showing why update delivery matters as much as the original software design.
How large is the security problem described in the article, including the average number of hacked TP-Link routers Microsoft observed?
The article describes a substantial but specific security problem involving compromised TP-Link routers. Microsoft reported in 2024 that a hacking group it believed was in China had created a network of hacked small-office and home routers. Those devices supported password-spray attacks, which try common passwords across many accounts. TP-Link routers made up most of that network.
Microsoft counted an average of 8,000 hacked devices active at any time. The complaints also cite Russian military intelligence hackers, whom the FBI said compromised TP-Link routers through CVE-2023-50224. They changed DNS settings and collected passwords and login tokens. Devices from other brands were also part of Microsoft’s network, so the problem was not limited to TP-Link.
Three complaints cite five additional flaws in devices supplied by ISPs. Researchers published technical details on October 8, and fixes exist. Those fixes reach users through their ISPs. The evidence shows real exploitation, but it does not establish that every TP-Link router is compromised or that customer data was broadly taken.
What do the states say TP-Link misrepresented about HomeShield, software updates, its ties to China, and its privacy policies?
The states’ central argument is that TP-Link’s public claims did not match important security and business realities. The Florida, Montana, and Nebraska complaints quote HomeShield as saying it “covers all security scenarios.” They contrast that promise with hacked routers and models that no longer receive fixes, including two Archer AX21 versions said to have reached end of life in May 2024.
The complaints also challenge TP-Link’s description of its restructuring. The company said it now had “entirely different ownership, management, and operations” from TP-Link Technologies. The states point to shared employment in China and parts for Vietnamese-made U.S. routers sourced from or through China. They say these facts undermine the impression of complete separation.
Finally, the complaints say privacy policies omit a Chinese-law risk. Tether, Tapo, Deco, and Kasa Smart apps collect email addresses, location, and phone identifiers. The states say a 2017 Chinese intelligence law could expose that information to Chinese agencies. They describe risk, not proven access.
What could happen to TP-Link and its customers if the states win their cases?
If the states win, TP-Link could face court-ordered changes under consumer-protection laws. Florida seeks a permanent order against the challenged practices, money made from them, and $10,000 for each willful violation. Montana seeks up to $10,000 per violation. These remedies could make misleading security or business claims costly.
Nebraska seeks additional disclosures. It wants TP-Link ordered to tell buyers where products and parts come from, explain its ties to China, and identify known vulnerabilities that have been exploited. Such an order could give customers more information before they buy or use the products. The article does not say a court has granted any request.
The cases could also increase pressure for clearer security communications and updates, but the article does not predict a specific technical remedy. TP-Link denies the claims and says it is an independent U.S. company that does not share customer network data with foreign governments or unauthorized third parties. The lawsuits remain unresolved.
How can a company's ownership, supply chain, and obligations under Chinese law create data-access concerns even when there is no evidence that the Chinese government accessed customers' data?
Data-access concerns can arise from several connections, even without proof that anyone actually accessed the data. A company’s ownership or former affiliation may raise questions about who controls it. A supply chain involving China can raise questions about where components, software, or operations are handled. The complaints say TP-Link Systems was affiliated with TP-Link Technologies before a 2024 restructuring.
The states also point to Chinese law. They say TP-Link apps collect email addresses, location, and phone identifiers, and that a 2017 Chinese intelligence law could expose such data to Chinese intelligence agencies. They cite parts for Vietnamese-made routers being sourced from or through China. These facts form the basis of a possible access risk, not proof of actual collection by Chinese authorities.
The complaints from Florida, Montana, and Nebraska do not allege that the Chinese government obtained customers’ data through TP-Link. Iowa’s release uses stronger language in places, but also describes access as something that could happen. TP-Link says it is independent and will not share customer network data with foreign governments.
How does a home router connect devices to the internet, and how can attackers exploit it to change DNS settings, steal credentials, or use it in attacks on others?
A home router connects phones, computers, and other devices to the internet. It directs traffic between those devices and outside services, while applying network settings such as DNS instructions. That central position makes the router an attractive target. A flaw in its firmware can give attackers control over how the network communicates.
The article describes a concrete example. FBI officials said Russian military intelligence hackers compromised TP-Link routers through CVE-2023-50224. The hackers changed DNS settings, which can redirect requests for online services, and collected passwords and login tokens. Microsoft also reported a network of hacked small-office and home routers used for password-spray attacks. TP-Link devices made up most of that network.
A compromised router can therefore harm its owner and help attack others. The article reports an average of 8,000 hacked devices active in Microsoft’s network at any time. It also says devices from other brands were involved. Updates can reduce exposure, and fixes for five cited flaws reach affected users through their ISPs.
Key Facts:
📌 Five states sued TP-Link over security and China-related marketing claims.
📌 Texas filed in February; four other states filed October 6.
📌 TP-Link denies the allegations and plans to fight in court.
📌 Firmware is built-in software that controls a router’s operation.
📌 A cited flaw let hackers change DNS settings and collect passwords.
📌 Fixes for five cited flaws reach users through their ISPs.
📌 Microsoft observed an average of 8,000 hacked devices active at once.