
Attorneys general in Florida, Iowa, Nebraska, and Montana have filed lawsuits against TP-Link Systems, alleging it misled consumers about its routers’ security, its separation from China, and risks to their personal data.
The legal actions target the California-based company under state consumer protection laws. TP-Link denies the allegations and says it will contest them in court.
Florida Attorney General James Uthmeier, Iowa’s Brenna Bird, Nebraska’s Mike Hilgers, and Montana’s Austin Knudsen accuse the company of making security assurances while failing to disclose vulnerabilities and continuing dependencies on Chinese operations.
TP-Link sells home and small-office routers, mesh Wi-Fi systems, and smart home products. The states cite congressional testimony that TP-Link holds at least 60% of the US retail market for Wi-Fi systems and home and small-office routers.
Security and privacy allegations
The states challenge TP-Link’s claims that it separated from its Chinese operations and manufactures US-market devices in Vietnam. They allege that substantial research, development, and manufacturing remain in China, and that supply-chain relationships undermine the company’s assurances.
Florida’s 59-page complaint claims that, by value, just 0.5% of the components used at TP-Link’s Vietnamese factory are purchased in Vietnam, with the remaining inputs imported from or through China. Nebraska also highlights the use of a contractor with ties to the Chinese military to build the facility.
The Florida complaint cites exploitation of TP-Link routers by Chinese threat actors and Russia’s GRU, arguing that security marketing concealed risks from known firmware flaws.
It specifically names the TL-WR940N, Archer C7 versions 2 and 3, and Archer AX21 versions 1 and 1.20, alleging that consumers were left with vulnerable devices lacking security support and automatic firmware updates.
The privacy allegations concern TP-Link’s Tether, Deco, Tapo, and Kasa Smart apps. Florida says they collect information including email addresses, precise location, and mobile phone identifiers while allowing sharing with affiliates without adequately explaining potential exposure to Chinese intelligence laws.
These are allegations of undisclosed risks and deceptive practices, not a court finding that TP-Link actually supplied customer data to China.
Florida seeks an injunction, disgorgement of allegedly ill-gotten gains, and penalties of $10,000 per willful violation, rising to $15,000 for certain violations involving protected consumers.
Montana seeks an injunction and $10,000 per violation, while Nebraska seeks civil penalties, fees, and other relief.
TP-Link rejects the claims
In its response, TP-Link said it had already provided regulators with documentation showing that it manufactures US-market devices in Vietnam and operates as an independent US company.
Corporate affairs officer Steve Kovsky described the coordinated lawsuits as “built on false premises.”
The company denied that its products grant foreign governments unauthorized network access. It said it complies with US privacy laws, performs comprehensive security testing, uses independent security laboratories, and helps customers address vulnerabilities.
TP-Link also said it does not, and will not, share customer network data with foreign governments or unauthorized third parties.
The lawsuits follow Texas Attorney General Ken Paxton’s earlier action against TP-Link, which raised similar allegations about security assurances and ties to China.
Router owners should check their exact model and hardware revision for firmware updates and support status, enable automatic updates where available, and replace devices that no longer receive security fixes.
It is also wise to change default admin passwords, disable remote administration panels if you don’t need them, and regularly check settings for suspicious changes.







Leave a Reply