FOUR US states have filed lawsuits against TP-Link Systems, alleging the router maker misled consumers about product security and China ties. Florida, Iowa, Montana, and Nebraska each filed complaints on 6 October 2026, drawing on state consumer protection laws.
The actions mirror a February suit in Texas and focus on TP-Link’s marketing claims, including HomeShield coverage and the notion of “100% safeguard.” The states cite congressional testimony about TP-Link routers being exploited in the Volt Typhoon and Flax Typhoon campaigns, and point to botnets and Russian activity targeting TP-Link devices. They also allege that certain models no longer receive automatic firmware updates. The actions seek injunctions, civil penalties, disgorgement of ill-gotten gains, and jury trials.
SEC Consult published technical details to back the complaints, outlining five vulnerabilities in the Aginet line of ISP-managed devices, tracked as CVE-2025-30237 through CVE-2025-30241. The flaws, disclosed by TP-Link in August, allow an unauthenticated attacker on the same network to fully compromise affected devices.
CVE-2025-30237 is an authentication bypass enabling a super‑administrator account and SSH access without credentials; CVE-2025-30238 permits a low-privilege user to perform administrator actions; CVE-2025-30241 is a web-interface command injection granting root privileges. CVE-2025-30239 derives from hardcoded encryption keys tied to device models, allowing extraction of passwords and Wi‑Fi credentials from configuration files.
CVE-2025-30240 requires physical access via a USB drive to read the device’s file system. TP-Link identified 65 affected devices, including mesh systems, routers, and PON/DSL devices, with ISP-customised variants also impacted. Updates are distributed by ISPs; users are advised to check management interfaces or contact their provider. SEC Consult refrained from releasing PoC exploits to avoid widespread exploitation prior to patching.