TP-Link Faces 5 State Lawsuits: Are Its Routers Still Legal in the US?

Five states have sued TP-Link over router security and disclosure claims. Here’s how the lawsuits, FCC restrictions, and firmware vulnerabilities affect existing owners.

Oct 8, 2026
TP-Link Faces 5 State Lawsuits: Are Its Routers Still Legal in the US?

TP-Link faces five state lawsuits over router security claims as federal restrictions affect authorization of new foreign-produced routers. Image generated by ChatGPT.

We may earn from vendors via affiliate links or sponsorships. This might affect product placement on our site, but not the content of our reviews. See our Terms of Use for details.

TP-Link faces lawsuits from five US states over allegations that it misled consumers about router security and its ties to China. Florida, Iowa, Montana, and Nebraska filed complaints on Oct. 6, 2026, following a Texas lawsuit in February. The cases raise questions about TP-Link’s security claims, but they do not prohibit Americans from using routers they already own.

The lawsuits coincide with federal restrictions on new foreign-produced router models. The Federal Communications Commission (FCC) adopted those restrictions in March, although previously authorized routers can generally still be sold and used.

For IT teams and consumers, the priorities are identifying vulnerable devices, confirming firmware support, and understanding which equipment faces purchasing restrictions.

The four new lawsuits accuse TP-Link Systems of misleading consumers about its products’ security and failing to adequately disclose its relationships with Chinese affiliates.

According to the Iowa Attorney General’s Office, the company’s security marketing created expectations that its routers could protect consumers from unauthorized access despite known vulnerabilities and supply-chain concerns.

The complaints challenge advertising claims surrounding TP-Link’s HomeShield security service and question whether the company’s disclosures adequately explain the implications of Chinese intelligence and cybersecurity laws.

The states are pursuing consumer protection claims, including allegations of misleading advertising and inadequate security disclosures. These allegations do not establish that TP-Link deliberately provided foreign governments access to customer networks.

TP-Link rejected the accusations in an Oct. 6 statement.

“The coordinated lawsuits are built on false premises,” said Steve Kovsky, corporate affairs officer at TP-Link Systems.

The company maintains that it is an independent US business, its US-market devices are manufactured in Vietnam, and allegations that its products grant foreign governments unauthorized network access are baseless.

The dispute now involves five states, including Texas, which filed its lawsuit on Feb. 17.

Advertisement

The lawsuits add to scrutiny of vulnerabilities affecting TP-Link networking equipment, including Aginet routers, modems, and mesh systems supplied through internet service providers.

Researchers at SEC Consult identified five vulnerabilities, CVE-2025-30237 through CVE-2025-30241, that could expose affected devices to unauthorized access or compromise.

The vulnerabilities involve different attack methods:

  • CVE-2025-30237: Authentication bypass that could let an attacker access privileged functions without valid credentials.
  • CVE-2025-30238: Authorization flaw allowing a low-privileged user to perform administrative operations.
  • CVE-2025-30239: Hardcoded cryptographic keys that could expose stored credentials and configuration information.
  • CVE-2025-30240: File exposure through a specially prepared USB device, requiring physical access.
  • CVE-2025-30241: Authenticated command injection that could allow execution of commands with elevated privileges.

The most serious attack scenarios could result in complete device compromise, although exploitation requirements differ. Some flaws require local network access or authentication, while the USB vulnerability requires physical access.

TP-Link’s security advisory lists affected models, firmware versions, and available fixes. Because some Aginet devices use ISP-specific firmware, customers may need to obtain patches through their provider.

Adam Marrè, chief information security officer at Arctic Wolf, raised concerns about the gap between security marketing and ongoing protection.

“What’s most concerning about the allegations against TP-Link is the gap between security promises and security outcomes. With the industry changing so rapidly, what provides a ‘100% safeguard’ today may not provide a 100% safeguard tomorrow.”

He added:

“Simultaneously, customers have a right to expect that the security being promoted to them is being taken seriously beyond just marketing claims.”

Marrè also emphasized the risks associated with poorly maintained network equipment.

“The vulnerabilities cited in the complaints are evidence of the prevalence of attackers targeting devices at the edge. They are often neglected when it comes to monitoring and slow to be updated.”

Advertisement

“Every internet-facing device is a potential foothold for attackers, and any company who fails to prioritize securing devices at the edge are creating risk for both their customers and the broader ecosystem.”

TP-Link has faced separate vulnerability disclosures involving consumer Archer routers. The company previously issued fixes for router security flaws affecting several Archer NX models.

These vulnerabilities warrant patching, but their existence does not establish the lawsuits’ allegations about corporate control or intentional foreign-government access.

What the FCC router ban means for TP-Link owners

The FCC added foreign-produced routers to its Covered List on March 23, following a federal national security determination.

The FCC’s public notice applies to routers produced outside the US, regardless of manufacturer nationality. It is not a TP-Link-specific restriction.

Covered equipment generally cannot receive new FCC equipment authorizations, which are required to market applicable wireless devices in the US.

However, previously granted authorizations remain valid unless separately revoked or restricted.

For buyers and businesses, the distinction is straightforward:

  • Existing owners: Previously authorized TP-Link routers do not have to be replaced solely because of the FCC decision.
  • Retailers: Previously authorized models can generally continue to be imported and sold.
  • Manufacturers: New foreign-produced router models generally require an applicable exception or conditional approval before receiving authorization.

The FCC created a conditional-approval process involving the Department of War and Department of Homeland Security. TP-Link has sought approval for new US-market models.

On Oct. 7, Nebraska Attorney General Mike Hilgers led a coalition of 21 state attorneys general urging the FCC to scrutinize the company’s application.

The letter adds pressure to TP-Link’s efforts to introduce new router models but does not revoke existing product authorizations.

The broader FCC router restrictions affect foreign-produced equipment across the industry, not just TP-Link.

Advertisement

Neither the lawsuits nor the FCC restrictions require immediate removal of existing TP-Link routers. Organizations should focus on firmware support, network exposure, and procurement requirements.

Four checks should take priority:

  1. Inventory affected equipment. Identify TP-Link and ISP-supplied Aginet devices, including hardware revisions and installed firmware.
  2. Confirm security patches. Check TP-Link’s advisory and contact the ISP for carrier-managed models. Do not assume retail firmware applies to ISP-customized hardware.
  3. Review network exposure. Restrict unnecessary remote management, disable unused services, and segment untrusted devices. Compromised routers have previously appeared in Flax Typhoon botnet activity.
  4. Check procurement plans. Verify FCC authorization for new models, review support commitments, and consider alternative suppliers where future availability remains uncertain.

Consumers can continue using previously authorized TP-Link routers, but should check that their model still receives security updates. Unsupported equipment may present a greater immediate risk than the ongoing litigation.

The five state lawsuits and FCC conditional-approval process will proceed separately. For organizations considering new TP-Link purchases, the key questions are whether the specific model has FCC authorization, whether security support remains active, and how firmware updates are delivered.

Also read: Organizations planning a wireless upgrade can compare Wi-Fi 8 vs Wi-Fi 7 to assess current router capabilities, compatibility, and costs.