$ techbeacon▋
CVE & Exploits

Four Additional States Join Lawsuit Against TP‑Link Over Router Security Claims and China Links

Four Additional States Join Lawsuit Against TP‑Link Over Router Security Claims and China Links

Four U.S. state attorneys general — Florida, Iowa, Montana and Nebraska — filed a joint lawsuit against networking equipment maker TP‑Link Systems on Oct. 6, expanding the legal challenge to five states after Texas initiated a similar suit in February. The complaint accuses the California‑registered subsidiary of deceiving consumers about the robustness of its home‑router security features and downplaying the company's operational ties to China.

The states allege that TP‑Link marketed its routers as "secure by design" while allegedly neglecting to disclose known vulnerabilities and the extent of firmware updates that could be remotely accessed. Prosecutors claim the firm failed to provide adequate safeguards against unauthorized intrusion, thereby exposing millions of households to potential cyber‑espionage and data theft.

Beyond product claims, the suit focuses on the company's corporate structure. Although TP‑Link operates a U.S. headquarters, the plaintiffs argue that its ultimate ownership and key engineering functions remain under Chinese control, a point they say the company obscured in its marketing and warranty documentation. The attorneys general contend that such omissions violate consumer‑protection statutes and could pose national‑security risks given the prevalence of Chinese‑manufactured networking gear in American homes.

The legal action follows a broader wave of scrutiny directed at Chinese technology firms after heightened tensions between Washington and Beijing. In recent months, federal agencies have issued advisories urging consumers to replace routers from vendors deemed high‑risk, and several states have passed legislation mandating stricter supply‑chain transparency for IoT devices. TP‑Link has previously defended its products, citing independent security audits and asserting compliance with U.S. regulations.

If the case proceeds to trial, it could set a precedent for how state consumer‑protection laws intersect with national‑security concerns in the tech sector. The plaintiffs are seeking injunctive relief to halt sales of the contested devices, restitution for affected consumers, and a court order requiring TP‑Link to disclose its corporate affiliations and security practices. The company has not publicly responded to the latest filing, but legal experts predict that settlement negotiations may intensify as the litigation moves forward, potentially prompting broader industry changes in how router manufacturers address security and transparency.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related