Four additional U.S. states have initiated legal proceedings against router manufacturer TP-Link Systems as of October 6, expanding the total number of states involved to five, with Texas having filed earlier in February. The lawsuits, filed by Florida, Iowa, Montana, and Nebraska, allege that the California-based company misrepresented the security of its routers and its independence from Chinese affiliations. TP-Link has refuted these claims and intends to contest them in court.
Allegations Against TP-Link
TP-Link Systems, headquartered in Irvine, California, was previously associated with TP-Link Technologies, a Chinese firm not named in the suits, until a restructuring in 2024. While the complaints from Florida, Montana, and Nebraska do not claim direct data access by the Chinese government, they highlight potential risks under Chinese law and note that state-backed hackers have exploited vulnerabilities in TP-Link’s routers.
Iowa’s legal announcement, however, makes stronger assertions, suggesting that TP-Link’s firmware could potentially enable Chinese government access to data. A subsequent letter from 21 state attorneys general to the FCC highlighted TP-Link’s attempt to gain approval for new router models in the U.S., raising security concerns.
Legal Claims and Security Concerns
The lawsuits, filed under consumer protection statutes, claim that TP-Link overstated its security features and its separation from Chinese operations. The complaints highlight that TP-Link’s promotional materials for its HomeShield network protection service promised comprehensive security, despite vulnerabilities in certain routers, such as the Archer AX21, which no longer receives updates.
Additionally, the complaints argue that TP-Link exaggerated its operational independence from China. They cite that only a small fraction of parts in its Vietnamese assembly plants are sourced locally, with the majority coming from or through China. Furthermore, the privacy policies of TP-Link’s various apps are criticized for potentially exposing user data to Chinese intelligence under a 2017 law.
TP-Link’s Defense and Cybersecurity Implications
In response, TP-Link has labeled the lawsuits as unfounded and counterproductive to national security efforts. The company maintains that its U.S. market routers are manufactured in Vietnam and emphasizes its independence from any foreign government control. It assures that no customer data is shared with unauthorized entities.
The lawsuits reference actual cyberattacks, highlighting that TP-Link routers were part of a botnet used for widespread password-spray attacks, as reported by Microsoft in 2024. Furthermore, the FBI disclosed a vulnerability exploited by Russian hackers in TP-Link devices. Despite these incidents, TP-Link has denied any deliberate inclusion of backdoors in its products.
Regulatory and Technical Challenges
The ongoing legal battles coincide with the FCC’s recent restrictions on foreign-manufactured consumer routers, requiring new models to meet stringent approval criteria. A letter from multiple attorneys general to the FCC underscores concern over TP-Link’s security claims and its production ties to China.
Moreover, the lawsuits highlight five security flaws in TP-Link devices, particularly those distributed by ISPs, which could allow unauthorized access and control. These vulnerabilities, disclosed in August, underline the persistent security challenges TP-Link faces, complicating its efforts to maintain consumer trust and regulatory compliance.
As these legal and technical developments unfold, the implications for TP-Link’s operations and reputation within the U.S. market remain significant. The outcome of these lawsuits could shape future industry standards and consumer protection policies.
