Four U.S. states – Florida, Iowa, Montana, and Nebraska – have filed lawsuits against router manufacturer TP-Link Systems, joining Texas in legal action against the company. The core allegations center on claims that TP-Link misled consumers regarding the security of its routers and the extent of its separation from Chinese affiliations. These legal actions, filed under consumer-protection laws, highlight significant concerns for security professionals and end-users regarding device trustworthiness and data privacy, as detailed by The Hacker News.
Overview of State Lawsuits Against TP-Link
The lawsuits contend that TP-Link advertised a level of security for its products that was not delivered and misrepresented its ties to China. The complaints also identify privacy policy omissions that could expose user data to foreign intelligence agencies under Chinese law. TP-Link denies these claims, asserting its independence and commitment to customer data privacy.
Misleading Security Claims and End-of-Life Devices
One central allegation is that TP-Link’s marketing, specifically for its HomeShield network protection service, promised to “cover all security scenarios” while some of its routers were demonstrably compromised, and certain models no longer receive security updates. A prime example cited in the complaints is specific versions of the Archer AX21, which TP-Link reportedly ceased updating in May 2024, reaching end-of-life (EOL). For security professionals, addressing TP-Link Archer AX21 end-of-life security and other EOL devices is critical, as they become increasingly vulnerable targets without ongoing patching and support.
Undisclosed China Ties and Supply Chain Concerns
The states further allege that TP-Link overstated its separation from its former affiliate, TP-Link Technologies, a Chinese company. Despite TP-Link’s claims of “entirely different ownership, management, and and operations” post-2024 restructuring, the lawsuits cite reports indicating a continued significant operational footprint in China. Furthermore, while TP-Link states its U.S. market routers are made in Vietnam, the complaints indicate that 99.5% of parts, by value, are sourced from or through China. This raises questions about mitigating TP-Link supply chain risks and the broader implications for hardware integrity and national security, especially given the U.S. Department of Defense’s listing of TP-Link Technologies as a Chinese military company.
Data Privacy Risks and Foreign Intelligence Laws
The third major claim focuses on TP-Link’s privacy policies. The lawsuits contend that apps like Tether, Tapo, Deco, and Kasa Smart collect sensitive user data, including email addresses, location information, and phone identifiers. Critically, the complaints highlight a potential risk where this data could be exposed to Chinese intelligence agencies under a 2017 Chinese intelligence law, even without direct access built into the products by TP-Link.
Confirmed Exploitation of TP-Link Routers
Beyond the allegations of misrepresentation, the lawsuits reference real-world incidents of TP-Link router exploitation. Microsoft reported in 2024 that a China-linked hacking group established a botnet predominantly comprising hacked small-office and home routers, with TP-Link devices forming the majority of an estimated 8,000 active devices. These compromised routers were used for password-spray attacks. Separately, the FBI revealed in April that Russian military intelligence hackers exploited a flaw, tracked as CVE-2023-50224, in certain TP-Link routers to alter DNS settings and collect login credentials. TP-Link stated that most products affected by this specific flaw had reached end-of-life. It is also noted that the “Horse Shell” backdoor found on some TP-Link routers was placed by a Chinese state-backed hacking group, not by TP-Link itself.
Actionable Recommendations
Given these significant concerns, security professionals and consumers should prioritize several actions:
- Firmware Updates: Regularly check for and apply the latest firmware updates from TP-Link or your Internet Service Provider (ISP). While fixes for the five flaws mentioned in the complaints exist, continuous vigilance is necessary.
- End-of-Life (EOL) Device Management: Identify and replace any EOL networking equipment, such as the Archer AX21 versions, as these devices no longer receive critical security patches, leaving them vulnerable to exploitation.
- Privacy Policy Review: Understand the data collection practices and privacy policies associated with any smart home or networking apps you use, particularly those from manufacturers with potential foreign intelligence law implications.
- Supply Chain Due Diligence: For organizations, implement rigorous supply chain risk management practices for all network infrastructure hardware, considering the origin of components and potential foreign government influence.
- Network Segmentation and Monitoring: Employ network segmentation to isolate sensitive systems and continuously monitor network traffic for anomalous activity that could indicate compromise, especially on consumer-grade routers often targeted in botnet operations.
Related: Comcast WiFi Motion: Privacy Concerns in Router-Based Sensing, China Military Bans Top Cybersecurity Firms for Procurement Violations