www.securityweek.com 8 Oct 2026, 10:24 UTC

Four US States Sue TP-Link Over Security Claims and Router Flaws

Four US States Sue TP-Link Over Security Claims and Router Flaws
CyberSIXT Evidence Panel Source marked as original reporting

FOUR US states have filed lawsuits against TP-Link Systems, alleging the router maker misled consumers about product security and China ties. Florida, Iowa, Montana, and Nebraska each filed complaints on 6 October 2026, drawing on state consumer protection laws.

The actions mirror a February suit in Texas and focus on TP-Link’s marketing claims, including HomeShield coverage and the notion of “100% safeguard.” The states cite congressional testimony about TP-Link routers being exploited in the Volt Typhoon and Flax Typhoon campaigns, and point to botnets and Russian activity targeting TP-Link devices. They also allege that certain models no longer receive automatic firmware updates. The actions seek injunctions, civil penalties, disgorgement of ill-gotten gains, and jury trials.

SEC Consult published technical details to back the complaints, outlining five vulnerabilities in the Aginet line of ISP-managed devices, tracked as CVE-2025-30237 through CVE-2025-30241. The flaws, disclosed by TP-Link in August, allow an unauthenticated attacker on the same network to fully compromise affected devices.

CVE-2025-30237 is an authentication bypass enabling a super‑administrator account and SSH access without credentials; CVE-2025-30238 permits a low-privilege user to perform administrator actions; CVE-2025-30241 is a web-interface command injection granting root privileges. CVE-2025-30239 derives from hardcoded encryption keys tied to device models, allowing extraction of passwords and Wi‑Fi credentials from configuration files.

CVE-2025-30240 requires physical access via a USB drive to read the device’s file system. TP-Link identified 65 affected devices, including mesh systems, routers, and PON/DSL devices, with ISP-customised variants also impacted. Updates are distributed by ISPs; users are advised to check management interfaces or contact their provider. SEC Consult refrained from releasing PoC exploits to avoid widespread exploitation prior to patching.

View full article

Article by CyberSIXT