Breaking
Cyber CrimeDeveloping Story

States sue TP-Link over China ties, security claims

Florida, Iowa, Montana, and Nebraska allege TP-Link misled buyers about router security and undisclosed reliance on Chinese suppliers.

··3 hours ago·6 min read
Fiber optic cables connected to a network switch in a server rack
Photo by Kirill Sh on Unsplash

Four state attorneys general have filed suit against TP-Link Systems, the California-based maker of routers and smart home devices, accusing the company of misleading consumers about how secure its products really are and about the extent of its ties to China. The action lands on a company whose gear sits in a large share of American homes and small offices, and it puts the national-security debate over foreign-made networking equipment directly in front of a state court.

Who is suing and what they allege

The attorneys general of Florida, Iowa, Montana, and Nebraska filed the complaint against TP-Link Systems. The suit accuses the company of deceptive and unfair marketing practices tied to its routers' security and its connections to the People's Republic of China. It also claims TP-Link concealed facts about its "past and ongoing ties to the People's Republic of China."

TP-Link is a major presence in US retail and the tech channel, particularly in consumer routers, and the complaint points to market data from Circana asserting roughly 36.6 percent US market share by units and 31 percent by dollars in 2024. The states argue that the company's assurances about security and supply-chain independence were misleading given its continued reliance on Chinese suppliers and laws that compel companies in China to cooperate with state intelligence.

The Vietnam relocation claim

A central factual dispute is whether TP-Link actually moved its manufacturing away from China. The company has previously claimed it relocated to Vietnam after severing ties with China, but the complaint alleges that only 0.5 percent of components used at its Vietnamese plant, measured by value, are bought in Vietnam. According to the states, "all other inputs" are imported "from or through China."

The complaint further claims that a US-designated Chinese military company carried out construction work at the Vietnamese factory. That allegation, if accurate, would directly challenge TP-Link's public assurances about the security of its supply chain. TP-Link has denied the characterization of its operations and says its US-sold devices are manufactured in Vietnam.

Marketing under scrutiny

Lawyers for the states pointed to specific snippets from TP-Link's marketing materials to argue that the company overpromised on security. These included claims that its HomeShield product "covers all security scenarios" and, on a version of its website available in November 2025, provides a "100 percent safeguard" for network security.

The complaint argues those assurances were misleading because TP-Link routers contained critical vulnerabilities. It cites the company's privacy policies, which the states allege permit TP-Link to collect customer data and share it with affiliates, without disclosing how its Chinese connections and China's intelligence laws could expose that information to Chinese intelligence agencies.

What former NSA official testified

The complaint references 2025 testimony from former NSA cybersecurity director Rob Joyce, who said TP-Link's share of the US retail market for Wi-Fi systems and small-office/home-office (SoHo) routers was at least 60 percent. The states also cite Joyce's testimony that TP-Link routers were among the brands exploited in the China-linked Volt Typhoon and Flax Typhoon campaigns.

Those campaigns have been attributed to Chinese state-backed hackers, and the complaint cites exploitation of TP-Link devices by both Chinese and Russian state-backed hackers as part of its case that the company's security representations did not match reality.

The company's defense

TP-Link has rejected the lawsuits outright. Steve Kovsky, corporate affairs officer for TP-Link Systems Inc., said the suits rest on false premises, do nothing to advance national security, and unfairly penalize a US company. He added that the company has spent months providing officials with documentation showing it is not owned or controlled by any foreign government and that its US-sold devices are manufactured in Vietnam.

"Any claims that our products present a threat to user security or grant unauthorized network access to foreign governments are baseless," he said. "TP-Link Systems is a US company that complies with US privacy and data protection laws. We perform comprehensive security testing and rely on trusted third-party security labs for additional scrutiny to ensure our products meet the highest security standards and are recognized as among the most secure on the market."

— Steve Kovsky, corporate affairs officer for TP-Link Systems Inc.

Kovsky continued: "We meet or exceed all industry best practices for monitoring and preventing vulnerabilities and actively support our customers to mitigate any issues that occur as they are identified. We do not, and will not, share customer network data with foreign governments or unauthorized third parties."

He also said: "We stand fully behind the security of our products, the integrity of our company and our people, and our commitment to serving the best interests of our customers in the United States and globally. We look forward to refuting these baseless allegations in court."

Pressure from other states and Washington

This is not the first legal challenge of its kind. The allegations echo those made by Texas Attorney General Ken Paxton, whose office sued TP-Link earlier this year over its Chinese connections and router security.

Federal officials have also been weighing action. US officials began considering restrictions on TP-Link router sales in 2024. In March 2026, the FCC imposed broader restrictions on new foreign-produced router models, barring new equipment authorizations unless an exemption is granted. The FCC action did not automatically ban previously authorized models.

What the states want

The complaint asks the court to hold TP-Link accountable for what the states describe as deceptive marketing and concealment regarding its China ties. It cites the company's repeated firmware vulnerabilities and its alleged subjection to Chinese laws that force companies to cooperate with state intelligence as reasons the security assurances were misleading.

Iowa Attorney General Brenna Bird said: "Iowans' sensitive data and our national security is at risk because of TP-Link and their connection to the communist Chinese government. TP-Link tells Iowans its routers are safe, our personal data is secure, and that they have no ties to China. They are not telling the truth. It's time to hold China and China-backed companies accountable."

Montana Attorney General Austin Knudsen said: "TP-Link's false statements and deceptive advertising are a violation of Montana law. As a result of their nefarious practices, millions of Americans have unknowingly invited a foreign adversary into their living rooms and put their personal information at risk. I will do everything I can as Attorney General to hold TP-Link accountable and protect our privacy and security."

Why this matters beyond the courtroom

For anyone who owns a TP-Link router — and given the market-share figures, that is a substantial slice of US households and small businesses — the suit raises uncomfortable questions about how much weight to put on a vendor's security marketing. The states' core allegation is not that every TP-Link device is compromised, but that the company's public claims about security and supply-chain independence did not match the underlying facts. If a court agrees, the precedent could reach well past TP-Link to how foreign-linked hardware makers describe their products in the US.

The case also sits at the intersection of consumer protection and national security. State attorneys general are using deceptive-marketing law to go after supply-chain and intelligence concerns that federal regulators have only begun to address through equipment authorization rules. That approach, if it succeeds, could give states a new tool for scrutinizing foreign-made networking gear even when federal restrictions are narrow or slow to arrive.

For businesses that rely on TP-Link equipment, the practical takeaway is to treat vendor security claims as a starting point rather than a guarantee. The complaint's emphasis on critical vulnerabilities and known exploitation in state-backed campaigns suggests that, whatever the legal outcome, the devices have been a target. Kovsky's statement that the company will refute the allegations in court means the dispute is likely to run for some time, leaving customers to weigh the claims themselves in the meantime.

#tp-link#china#routers#security#lawsuit

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories