TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
Four US states sue TP-Link over misleading security claims, citing Aginet ISP router flaws enabling unauthenticated full device compromise.
Attorneys general of Florida, Iowa, Montana, and Nebraska filed consumer protection lawsuits against TP-Link Systems on October 6, alleging misleading security marketing and undisclosed China ties, following a similar Texas suit in February. The complaints cite five vulnerabilities, CVE-2025-30237 through CVE-2025-30241, affecting 65 Aginet ISP-managed devices, disclosed by SEC Consult, whose technical details were published October 2; CVE-2025-30237 allows unauthenticated attackers to create a super-administrator account with SSH access. Several exploited models lack automatic firmware updates and no longer receive patches, with fixes distributed via ISPs. TP-Link calls the lawsuits baseless, while 21 state attorneys general urged the FCC to scrutinize the company's request to sell new router models in the US.