Four US states sue TP-Link over deceptive security marketing, China ties, and Aginet router flaws
Attorneys general in Florida, Iowa, Montana, and Nebraska sued TP-Link Systems on October 6, 2026, alleging deceptive router-security marketing and undisclosed reliance on Chinese suppliers, citing Volt Typhoon and Flax Typhoon exploitation and five flaws…
Attorneys general in Florida, Iowa, Montana, and Nebraska filed consumer protection lawsuits against TP-Link Systems on October 6, 2026, alleging misleading router-security marketing and undisclosed China ties. The complaints cite TP-Link's roughly 36.6% US unit share in 2024 and claim that despite shifting assembly to Vietnam, its devices still depend almost entirely on Chinese components. They also cite exploitation of TP-Link routers in the Volt Typhoon and Flax Typhoon campaigns. On the technical side, the complaints reference five vulnerabilities — CVE-2025-30237 through CVE-2025-30241 — affecting 65 Aginet ISP-managed devices (routers, modems, and mesh systems), disclosed by SEC Consult, whose technical details were published October 2, 2026. CVE-2025-30237 allows unauthenticated attackers to create a super-administrator account with SSH access; several affected models lack automatic firmware updates and no longer receive patches, with fixes distributed via ISPs. TP-Link calls the lawsuits baseless, says it is a US company that manufactures US devices in Vietnam, and denies sharing network data with foreign governments. The suits follow a similar Texas lawsuit filed in February 2026 (per SecurityWeek; The Register did not specify the date), come after the FCC limited new foreign-produced router authorizations in March 2026, and coincide with 21 state attorneys general urging the FCC to deny TP-Link approval to sell new router models in the US.
- Attorneys general in Florida, Iowa, Montana, and Nebraska sued TP-Link Systems on October 6, 2026, over allegedly deceptive security marketing and undisclosed China ties.
- The complaints cite TP-Link's roughly 36.6% US router unit share in 2024.
- Despite assembly in Vietnam, TP-Link devices still depend almost entirely on Chinese components, according to the complaints.
- The complaints cite exploitation of TP-Link routers in the Volt Typhoon and Flax Typhoon campaigns.
- Five vulnerabilities — CVE-2025-30237 through CVE-2025-30241 — affect 65 Aginet ISP-managed devices (routers, modems, and mesh systems); SEC Consult published technical details on October 2, 2026.
- CVE-2025-30237 lets unauthenticated attackers create a super-administrator account with SSH access.
- Several affected models lack automatic firmware updates and no longer receive patches; fixes are distributed via ISPs.
Coverage timelineoldest first · each row is one article
- · 1d agoUS states sue popular kitmaker TP-Link over China risks
The Register · Security· 66
Four US states sued TP-Link, alleging deceptive router-security marketing and hidden reliance on Chinese suppliers.
- · 12h agoTP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
SecurityWeek· 55
Four US states sue TP-Link over misleading security claims, citing Aginet ISP router flaws enabling unauthenticated full device compromise.
Vulnerabilities in this storyAll →
- CVE-2025-302378.7<1%The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain…published
- CVE-2025-302388.6<1%In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations