bytevyte
bytevyte
Language

TP-Link Router Lawsuits Spread to Five States as 21 AGs Press FCC

TP-Link router lawsuits now span five states as 21 attorneys general urge the FCC to scrutinise its new-model approval, and TP-Link denies the claims.

TP-Link router lawsuits

TP-Link Systems is fighting consumer-protection cases in five US states while a 21-state coalition presses federal regulators to scrutinise its next product launch. The TP-Link router lawsuits, filed by Florida, Iowa, Nebraska and Montana on October 6, 2026, accuse the company of overstating how well its hardware protects buyers and of concealing how much of its supply chain still runs through China.

Texas filed a comparable case in February, which brings the total to five state actions. Each of the new complaints rests on its own state's consumer-protection statute rather than federal law, so the company must answer broadly similar factual allegations under five separate legal tests and five separate penalty regimes.

What the States Allege

The complaints target two things: the security assurances TP-Link puts in front of buyers, and the origin story behind its hardware. Nebraska Attorney General Mike Hilgers alleges the company never disclosed continuing ties to a Chinese military contractor, and that its routers remain vulnerable to exploitation by Russian intelligence services and by hackers affiliated with the Chinese state.

Iowa Attorney General Brenna Bird filed under the Iowa Consumer Fraud Act and disputes TP-Link's position that its routers are built in Vietnam. Her office argues that nearly all components are imported from China or routed through it, and that the firmware shipped on the devices gives the Chinese government a path into Iowans' devices and data.

Florida Attorney General James Uthmeier has framed the router as the digital entry point to a household network. His state is seeking civil penalties of up to $10,000 for each wilful violation under its Deceptive and Unfair Trade Practices Act. Montana Attorney General Austin Knudsen joined the same-day filings. The privacy allegations reach the Tether, Deco, Tapo and Kasa Smart apps, which customers use to manage their devices.

StateAttorney GeneralLegal basisNotable element
FloridaJames UthmeierDeceptive and Unfair Trade Practices ActSeeks up to $10,000 per wilful violation
IowaBrenna BirdIowa Consumer Fraud ActFirmware allegedly opens devices and data to Chinese government access
NebraskaMike HilgersState consumer protection lawAlleges undisclosed ties to a Chinese military contractor
MontanaAustin KnudsenState consumer protection lawPart of the coordinated four-state filing

The scale of the market is part of the argument. One complaint puts TP-Link's US unit share at about 36.6% in 2024, while another filing claims the company controls close to 60% of the market. The two figures rest on different definitions of what counts, and the states lean on both to argue that one vendor's security practices touch a wide slice of American households.

TP-Link denies the allegations. The company says the lawsuits rest on false premises, that devices sold in the United States are manufactured in Vietnam, and that claims its products grant foreign governments unauthorised network access are baseless. It has said it will contest the cases in court.

The corporate history sits at the centre of the dispute. The TP-Link brand originated in Shenzhen, and the operating entity moved its global headquarters to Irvine, California, in 2024. The states argue that relocation did not cut the underlying reliance on Chinese research, development and manufacturing, and that buyers were never told how much of the operation stayed in place.

The FCC Front

One day after the court filings, Nebraska led 21 state attorneys general in a letter to the FCC. The letter raises concerns about TP-Link routers while the company seeks conditional approval to sell new router models in the United States. That request hands the states a second lever. Even if the consumer cases take years to resolve, the approval process creates a nearer-term deadline for regulators to weigh the same security questions.

Background sharpens the stakes. TP-Link drew a US government investigation in 2024 over how it handled router security flaws that had been linked to Chinese hacking groups, and the FCC has since moved to restrict consumer-grade routers tied to certain supply chains. The current push arrives with TP-Link holding a large share of the US router market, a figure the states cite to argue that the consequences extend well past individual households.

The two tracks carry different remedies, and that difference explains why the states are running them in parallel. A consumer-protection win yields money and mandated disclosure; the FCC route can condition or block market access. Only the regulatory track can change what ships to US shelves in the next product cycle, which is why the approval request, not the court calendar, is the nearer threat to TP-Link's US revenue.

What It Means for Router Owners

None of the allegations has been proven, and TP-Link has not been found liable in any of the five cases. For households already running TP-Link hardware, the practical question is firmware. Three of the complaints cite five flaws in ISP-managed routers whose fixes ran into 2026, which makes patch status the concrete thing a buyer can verify today.

Firmware is often the failure point a household cannot fix on its own. Where an internet provider supplies and manages the router, the update path sits with the ISP rather than the customer, and the filings single out that arrangement: three of the four complaints point to five flaws in ISP-managed devices whose fixes stretched into 2026.

Owners can check the firmware version and update status for their model through the TP-Link app or the router's admin panel, and can confirm whether the device still receives security patches. Anyone weighing a replacement has a clearer reason to compare patch cadence and support windows across brands instead of defaulting to the cheapest unit on the shelf.

Why this matters

The TP-Link router lawsuits shift a national-security argument into consumer courtrooms, where the standard is whether buyers were misled rather than whether a network is safe. That framing matters for anyone who bought a router on the strength of a security claim. The FCC letter adds a second front with a faster clock, and the outcome will shape what assurances router makers can put on a box.

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.