Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Government

TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.

TP-Link vulnerabilities

Four US states have sued TP-Link Systems, accusing the router maker of misleading consumers about the security of its products and its ties to China.

The attorneys general of Florida, Iowa, Montana, and Nebraska filed the lawsuits on October 6 in their respective state courts. Each relies on its state’s consumer protection laws. Texas filed a similar lawsuit against the company in February.

The new state complaints, which are nearly identical, argue that TP-Link’s marketing overstates the protection its devices provide. They single out claims that the company’s HomeShield service “covers all security scenarios” and, as recently as November 2025, offered a “100% safeguard.”

To counter those claims, the states cite congressional testimony that TP-Link routers were exploited in the Volt Typhoon and Flax Typhoon campaigns. They also point to botnets used by Chinese threat actors for password spraying attacks, and to Russian hackers targeting TP-Link routers.

According to the complaints, several of the exploited models do not support automatic firmware updates and no longer receive security updates.

The states also take aim at TP-Link’s claimed separation from China. They allege that much of its research, development, and manufacturing remains there, and that only 0.5% of the components used at its Vietnam factory, by value, are bought in Vietnam.

Advertisement. Scroll to continue reading.

The complaints further claim that TP-Link’s privacy policies do not disclose that its Chinese affiliates are subject to China’s intelligence law. The states also say TP-Link fails to disclose 2021 Chinese regulations that require newly discovered vulnerabilities to be reported to the government.

The complaints seek injunctions, civil penalties, and the return of money obtained through the alleged violations, and request jury trials.

SEC Consult details ISP router flaws named in the complaints

To show that TP-Link’s security problems persist, the complaints cite five vulnerabilities, tracked as CVE-2025-30237 through CVE-2025-30241, that TP-Link disclosed in August. The issues affect the company’s Aginet line of ISP-managed mesh systems, routers, and modems.

On Thursday, SEC Consult, whose researchers discovered the flaws, published technical details.

“These vulnerabilities allowed an unauthenticated attacker on the same network to fully compromise the affected device,” SEC Consult said.

The most severe of the bugs, CVE-2025-30237, is an authentication bypass in the device’s web server. An attacker with access to the web interface could abuse it to create a super-administrator account and enable SSH access, without any credentials.

CVE-2025-30238 allows a low-privileged user to perform actions meant for administrators. CVE-2025-30241 is a command injection issue in the web interface that lets an authenticated attacker run commands with root privileges.

CVE-2025-30239 stems from the use of hardcoded encryption keys, tied only to the device model, to protect configuration files and backups. An attacker who obtains these files and extracts the keys from the firmware can recover user passwords, Wi-Fi credentials, and, depending on the configuration, credentials used for remote management by the ISP.

The fifth issue, CVE-2025-30240, requires physical access. An attacker could plug in a specially prepared USB drive to read the device’s entire file system.

TP-Link identified 65 affected devices, including mesh systems, routers, fiber (PON) devices, and DSL modems. Its advisory notes that ISP-customized variants of these models are also affected.

SEC Consult began reporting the flaws to TP-Link in December 2024. The vendor said in January 2025 that the initial issues were fixed, but identifying all affected models took until July 2025. The rollout of fixes, which included custom firmware for affected ISPs, stretched into 2026.

TP-Link says firmware updates for the affected devices are distributed by ISPs. It advises users to check their device’s management interface or app for updates and to contact their ISP if none are available. 

SEC Consult did not release PoC exploit code due to concerns that many vulnerable devices remain unpatched.

In an October 6 statement, TP-Link rejected the allegations.

“The coordinated lawsuits are built on false premises. They do nothing to advance national security while unfairly penalizing an industry-leading U.S. company,” said Steve Kovsky, TP-Link’s corporate affairs officer.

The company said it had spent months providing state regulators with documentation showing that its US devices are manufactured in Vietnam and that it is not owned or controlled by any foreign government.

“Any claims that our products present a threat to user security or grant unauthorized network access to foreign governments are baseless,” TP-Link said.

On October 7, Montana Attorney General Austin Knudsen joined a coalition of 21 state attorneys general in a letter urging the FCC to scrutinize TP-Link. The company is seeking conditional approval to sell new router models in the US, after the FCC moved in March to add routers produced in foreign countries to its Covered List.

“TP-Link routers should be considered a Trojan horse planted by the Chinese Communist Party to spy on Americans. I hope the FCC seriously considers TP-Link’s concerning practices and declines to grant the conditional approval they are seeking for the sake of our national security,” Knudsen said.

Related: TP-Link Patches High-Severity Router Vulnerabilities

Related: TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover

Related: Hackers Fail to Exploit Flaw in Discontinued TP-Link Routers

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Rapid7 has named Rik Ferguson as VP of Security Intelligence.

Cytactic has appointed Tim Brown as CSO.

Scott Simkin has joined Vega as CMO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.