The box that controls nearly every device in your home has become the center of a widening national-security fight.
Florida, Iowa, Montana and Nebraska have filed lawsuits against TP-Link, accusing the router maker of misleading American consumers about its cybersecurity, its continuing connections to China and the risks surrounding the personal data that passes through its products.
Texas filed a similar case earlier this year. That means five states are now pressing the same basic question: Did millions of Americans buy what they thought was an ordinary home router without being told the full story about who built it, where its components came from and who might be able to exploit it?
Florida Attorney General James Uthmeier called a router the “digital front door” to a family’s home network. The legal fight quickly drew attention from technology watchers:
TP-Link forcefully denies that it is controlled by China or poses a unique threat. The courts have not found the company liable for the claims in these new complaints.
Still, five states are now willing to put closely related allegations before a judge. That makes this much bigger than another warning about changing a Wi-Fi password.
The Iowa Attorney General’s office alleges that TP-Link controls roughly 60 percent of the American market for networking devices and repeatedly marketed its products as secure while concealing meaningful ties to China.
Iowa’s filing says significant research, development and manufacturing operations remain in China even though TP-Link says its American business separated from its former Chinese affiliate and manufactures U.S.-market routers in Vietnam. The state further alleges that most components moving through the Vietnam plant originate in or pass through China.
Iowa also points to warnings from the FCC, NSA and Microsoft about compromised routers. A hijacked router can become a surveillance point, a path into other devices or part of a botnet used to attack targets far beyond the home where it sits.
That makes this story different from a normal product dispute. A router directs the traffic from laptops, phones, cameras, televisions, smart-home devices and often a family’s work computer.
One current-news account summarized the growing state action this way:
Nebraska Attorney General Mike Hilgers makes an additional supply-chain allegation. His office says TP-Link used a contractor with ties to the Chinese military to construct its Vietnam manufacturing facility and still depends on major research and manufacturing operations in China.
Nebraska’s case says the company’s products have been vulnerable to exploitation by state-affiliated Chinese hackers and Russian intelligence. It seeks civil penalties and an order preventing TP-Link from making what the state describes as misleading security and corporate-separation claims.
The lawsuit also invokes China’s 2017 National Intelligence Law, which requires Chinese citizens and organizations to assist state intelligence work when ordered. The legal and factual question now moving toward court is whether TP-Link’s current structure leaves its U.S. operation meaningfully exposed to that system.
The public reaction has focused on how ordinary these devices look—and how much trust Americans place in them:
The state cases did not appear out of nowhere.
A bipartisan House Select Committee letter asked the Commerce Department in 2024 to investigate whether TP-Link posed a national-security risk. Lawmakers noted that the company sold products in more than 170 countries and that TP-Link devices had been offered through military exchanges to service members and their families.
The letter cited campaigns in which state-backed hackers exploited small-office and home-office routers. It also referenced a Justice Department operation that removed Volt Typhoon malware from hundreds of compromised routers across the United States.
That history matters, but a hacker exploiting a vulnerable device does not prove that its manufacturer cooperated with the attacker.
The state lawsuits go further. They allege deceptive conduct involving corporate ties, manufacturing, security claims and potential access to consumer data—claims that will now have to survive litigation and evidence.
TP-Link says the accusations are false. The company describes itself as a U.S.-headquartered business based in Irvine, California, says it split from TP-Link China in 2024 and insists that no government controls the design or production of its routers.
TP-Link also disputes the 60-to-65-percent market-share figures frequently used by critics. It cites Circana data putting its 2024 U.S. consumer-router share at 36.6 percent by units and 31 percent by dollars.
The company argues that Chinese threat groups have targeted routers from many manufacturers, especially devices whose owners failed to install updates. It says singling out TP-Link ignores an industry-wide security problem and that its own practices meet or exceed U.S. standards.
TP-Link’s response matters because no court has settled these claims. The lawsuits, however, are real and multiplying.
Five states are now alleging that the company’s public story about independence, manufacturing and security does not match the reality behind the product. At the same time, federal officials have spent years examining the national-security risks surrounding foreign-made networking equipment.
For American consumers, the question is painfully simple.
If the small box handling every password, camera feed, financial login and private message in a home carries a hidden risk, people have a right to know before they plug it in—not years later, after lawyers and intelligence agencies finally start comparing notes.
This is a Guest Post from our friends over at WLTReport. View the original article here.
The post Four States Sue TP-Link, Say Popular Routers Put Americans’ Data At Risk appeared first on 100PercentFedUp.com.
Continue reading...
[H/T 100PercentFedUp]