Security News

Four US States Sue TP-Link Over Router Security Claims and China Ties

The Register · 8 Oct 2026
Key Takeaway Treat any security claim from a router vendor with caution, keep your router firmware up to date, and replace devices that no longer receive security updates.

Four US states, Florida, Iowa, Montana and Nebraska, have filed a lawsuit against TP-Link, a major maker of routers and smart home devices. The complaint accuses California-based TP-Link Systems, whose brand originated in Shenzhen, of deceptive and unfair marketing about the security of its routers and its connections to China. It cites exploitation of TP-Link devices by Chinese and Russian state-backed hackers, along with repeated firmware vulnerabilities. TP-Link rejects the allegations. Circana figures cited in the report put its US consumer router share at around 36.6 percent by units in 2024.

The states also allege the company concealed its past and ongoing ties to China. They claim it still relies on Chinese companies for research, development and manufacturing, despite earlier statements that it had moved operations to Vietnam. According to the complaint, only 0.5 percent of components at its Vietnamese plant, by value, are bought in Vietnam, with all other inputs imported from or through China. It further alleges that a US-designated Chinese military company did construction work at the factory, and that Chinese laws can compel firms to cooperate with state intelligence.

The lawyers also point to marketing claims, including that the HomeShield product "covers all security scenarios" and, on a November 2025 version of the website, offers a "100 percent safeguard" for network security. These are allegations in a lawsuit, not findings by a court.

Answering for this at board level? Our cyber governance framework ->

Summarised by CISO AI from The Register, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.