Four states filed lawsuits against TP-Link Systems, alleging that the company misled consumers about the security of its products and underplayed its ties to the Chinese government.
According to the lawsuit, TP-Link overstated its security protection by saying it covers “all security scenarios” and promised a “100% safeguard” as recently as November 2025.
The lawsuits, all of which are similar, seek injunctions, civil penalties, and the return of money obtained through the alleged infractions. They also request jury trials and seek damages for small companies that become unwitting accomplices to larger campaigns against critical infrastructure by Chinese threat actors, as well as Russian threat groups.
It should be noted that the four states filing suits are all red states: Florida, Iowa, Montana, and Nebraska — a similar lawsuit was filed in Texas in February.
Much of the concern here for enterprises revolves around TP-Link having about 60% of the U.S. retail market share for small-office, home-office (SOHO) routers — and that Chinese-linked threat actors exploit routers at small businesses and home offices to launch attacks on U.S. critical infrastructure. These routers are also used at mid-sized businesses and at branch offices of larger companies.
The lawsuit alleges exploits into TP-Link routers were used in the Volt Typhoon and Flax Typhoon campaigns linked to the Chinese and used by Chinese threat actor “Storm-0940” in password-spray attacks. Volt Typhon targeted the energy, rail, water, and aviation sectors, while Flax Typhoon aimed for the academic, government, and IT sectors.
According to the Florida lawsuit, the risk to consumers and the public at large is ongoing: many consumers keep their routers for years, and many of the compromised TP-Link models in homes do not support automatic firmware updates and no longer receive security support at all.
All of this activity has prompted the federal government into action. The Federal Communications Commission banned the sale of foreign-produced Wi-Fi routers in the U.S. in March. While Netgear and Amazon's Eero received temporary conditional exemptions, TP-Link has not yet been granted one, which means it still can't sell its new Wi-Fi 8 routers in the U.S.
John Gallagher, vice president at Viakoo, said the lawsuits serve as notice to TP-Link that its actions are not going unnoticed, but otherwise does nothing to address the core issue of OT/IoT security for organizations still using these routers: legal battles take years; threat actors strike in minutes.
Gallahger said the legal path might also prove that TP-Link just plans to play a shell game by offshoring production away from China to Vietnam without removing the vulnerabilities these routers have, but that it could wind up being an endless series of "catch me if you can" by claiming new products are clean even if they are not.
“Organizations need to take action immediately, starting with having an accurate inventory of TP-Link routers, followed by a decommissioning program,” said Gallagher. “Consumer grade routers and ones unsupported for new firmware updates have no place in enterprise situations.”
Adam Marrè, chief information security officer at Arctic Wolf, said he’s most concerned about the gap between security promises and security outcomes. With the industry changing so rapidly, what provides a “100% safeguard” today may not deliver a 100% safeguard tomorrow, said Marrè.
“Simultaneously, customers have a right to expect that the security being promoted to them is being taken seriously beyond just marketing claims,” said Marrè. “The vulnerabilities cited in the complaints are evidence of the prevalence of attackers targeting devices at the edge. They are often neglected when it comes to monitoring and slow to be updated. Every internet-facing device is a potential foothold for attackers, and any company who fails to prioritize securing devices at the edge are creating risk for both their customers and the broader ecosystem.”
Tony Turner, vice president of product at Frenos, said routers represent a supply chain dependency. Turner said teams need to know who supplies the software, who delivers updates, how to validate that it’s an authentic fix admins can trust.
Turner said teams should patch supported equipment when they can, but more urgently, reduce the attack surface by eliminating web and management interfaces on internet and untrusted networks and long-term, prioritize replacement of unsupported routers.
“Most edge networking device security failures are preventable through better hardening and configuration by removing access to the vulnerable attack surface,” said Turner.