TP-Link, a prominent router manufacturer, is under scrutiny as four US states have initiated legal actions against the company, citing deceptive marketing practices and concerns over ties to China. The lawsuits, filed by the attorneys general of Florida, Iowa, Montana, and Nebraska, challenge TP-Link’s claims regarding the security of its products and its operational independence from Chinese influence.
Allegations of Misleading Marketing
The lawsuits, which mirror a similar action by Texas earlier this year, focus on TP-Link’s marketing strategies. They argue that the company exaggerates the capabilities of its products, particularly its HomeShield service, which was promoted as offering comprehensive protection. The states reference congressional testimony where TP-Link routers were reportedly compromised in cyberattacks by Chinese and Russian actors.
Several router models mentioned in the complaints lack support for automatic firmware updates, leaving them vulnerable to exploitation. The states further contend that TP-Link’s operations are still heavily linked to China, with minimal manufacturing occurring outside the country.
Privacy and Security Concerns
The legal documents also highlight TP-Link’s inadequate disclosure of privacy policies. These policies allegedly fail to inform users that Chinese affiliates must comply with local intelligence laws, potentially compromising user data. Additionally, the states argue that TP-Link does not adequately disclose Chinese regulations that mandate reporting new vulnerabilities to the government.
The lawsuits seek injunctions, civil penalties, and restitution for affected consumers. They also demand a jury trial to address these alleged violations.
Details of Router Vulnerabilities
To substantiate their claims, the lawsuits refer to vulnerabilities disclosed by SEC Consult. Five specific flaws, identified in TP-Link’s Aginet line of products, were detailed. These include serious security issues such as an authentication bypass, command injection, and the use of hardcoded encryption keys. While TP-Link has issued firmware updates, many devices remain unpatched, raising concerns about ongoing risks.
TP-Link asserts that updates are distributed through ISPs and advises users to check for available updates. However, the persistent nature of these vulnerabilities continues to worry security experts.
TP-Link’s Response and Future Outlook
TP-Link has dismissed the lawsuits as unfounded. In a statement, the company emphasized its compliance with national security standards and denied any foreign government control over its operations. TP-Link also highlighted efforts to provide documentation to state regulators about its manufacturing practices in Vietnam.
Montana’s Attorney General, Austin Knudsen, alongside other state attorneys general, has urged the FCC to closely evaluate TP-Link as the company seeks approval to sell new router models in the US. The outcome of these legal actions and regulatory reviews could significantly impact TP-Link’s operations in the American market.
The ongoing scrutiny of TP-Link underscores the broader concerns over cybersecurity and foreign influence in technology product manufacturing, particularly regarding devices critical to national infrastructure.
