Four more US states sue TP-Link as details of ISP router flaws go public
Florida, Iowa, Montana and Nebraska sued TP-Link over security and China-ties claims, as SEC Consult detailed five flaws in 65 ISP-supplied Aginet devices.
At a glance
- Four state attorneys general filed consumer-protection suits on October 6, joining a Texas case from February.
- The complaints allege overstated security marketing, understated China ties and incomplete privacy disclosures; TP-Link calls them baseless.
- SEC Consult published details of CVE-2025-30237 to CVE-2025-30241, affecting 65 ISP-managed Aginet devices; fixes are delivered through ISPs.
- Users of ISP-supplied TP-Link devices should check for firmware updates and contact their provider if none is available.
The attorneys general of Florida, Iowa, Montana and Nebraska sued router maker TP-Link Systems on October 6, alleging the company overstated the security of its products and its independence from China, SecurityWeek and The Hacker News reported. The lawsuits arrived the same week SEC Consult published technical details of five vulnerabilities in TP-Link devices that internet service providers hand out to customers, putting fresh focus on home and small-office routers that are often left unpatched.
What happened
According to SecurityWeek, the four nearly identical complaints were filed in state courts under consumer protection laws, following a similar suit by Texas in February. They target marketing claims such as the HomeShield service covering "all security scenarios" and cite congressional testimony linking TP-Link routers to the Volt Typhoon and Flax Typhoon campaigns, Chinese botnets used for password spraying, and Russian hackers targeting the devices. The Hacker News notes that most of the complaints describe Chinese government access to customer data as a risk under Chinese law rather than an established fact, and that none alleges TP-Link built a backdoor.
The states also argue that much of TP-Link's research and manufacturing remains in China and that only 0.5% of component value at its Vietnam factory is sourced locally. They seek injunctions, civil penalties and restitution.
TP-Link corporate affairs officer Steve Kovsky said the suits are "built on false premises." The company says it has given regulators documentation that its US devices are made in Vietnam and that no foreign government owns or controls it.
Technical details
Separately, SEC Consult published details of CVE-2025-30237 through CVE-2025-30241, which TP-Link disclosed in August 2025. They affect the Aginet line of ISP-managed mesh systems, routers, fiber and DSL devices. According to SecurityWeek, the most severe, CVE-2025-30237, is an authentication bypass that lets an attacker on the same network create a super-administrator account and enable SSH. Other issues include privilege escalation, hardcoded per-model keys protecting configuration backups, file-system access via a crafted USB drive, and authenticated command injection with root privileges. SEC Consult did not release exploit code because many devices remain unpatched, and The Hacker News reports none of the flaws is in CISA's KEV catalog.
Who is affected
TP-Link lists 65 affected models, 27 of which are hit by all five flaws, plus ISP-customized variants. Because firmware is distributed by providers, end users may be unable to download fixes themselves.
What to do
TP-Link advises users to check for updates in the device's management interface or app and to contact their ISP if none is available. Organizations should also replace end-of-life routers that no longer receive security updates. In the US, 21 state attorneys general wrote to the FCC on October 7 urging scrutiny of TP-Link as it seeks conditional approval for new router models.
Related CVEs
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



