TP-Link is facing a legal and regulatory escalation in the United States after Florida, Montana, Iowa, and Nebraska filed lawsuits accusing the company of misleading consumers about its ties to China and the security level of the routers it produces. The lawsuits seek to halt the practices in question, compensate consumers in Florida, and impose fines under the consumer-protection laws of the states involved.
The move comes about six months after the U.S. Federal Communications Commission (FCC) announced a broad ban on consumer routers if they were manufactured wholly or partially outside the United States. Companies such as Netgear, Asus, Adtran, Amazon, Eero, Calix, Nokia, and Starlink have received exemptions, while TP-Link has not received one so far. As a result, the company cannot sell its latest Wi‑Fi 8 devices in the U.S. market, while sales continue for models that received approval before the ban.
The Core Allegations
The lawsuits claim that TP-Link marketed its routers to consumers as secure while concealing or downplaying its ties to China and the risks of exploiting vulnerabilities in its products. The states cited previous statements and security issues, including the exploitation of TP-Link devices by hackers linked to Chinese government entities and indications that vulnerabilities in these devices were exploited by Russia’s military intelligence agency, the GRU.
Florida Attorney General James Uthmeier said that Chinese state-backed hackers had exploited TP-Link devices located in American homes. The lawsuits also allege that the company failed to disclose to consumers ongoing ties to a Chinese military contractor or the risks associated with government entities exploiting its products.
The lawsuit refers to a report published by Bloomberg in April 2025, which stated that nearly all components at the company’s factory in Vietnam, except for local components representing 0.5 percent of the value of inputs, were imported from China. The states maintain that final assembly in Vietnam does not negate reliance on China or eliminate the need to disclose those ties.
TP-Link’s Response
The company rejected the lawsuits and described them as based on erroneous and coordinated claims. It said that TP-Link Systems devices sold in the United States are manufactured in Vietnam and that the company is an independent American company not owned or controlled by any foreign government. It added that it complies with U.S. privacy and data-protection laws, conducts comprehensive security testing, and uses independent laboratories, emphasizing that it does not share customer network data with foreign governments or unauthorized parties.
TP-Link was founded in China and moved its headquarters to California in October 2024, amid prominent investigations and attacks linked to the Chinese government, including a botnet whose devices were mostly TP-Link devices. The company says it has more than 550 employees in the United States, including hundreds of engineers at its California headquarters.
What Changes in Practice?
The ban does not mean that all TP-Link devices have disappeared from the U.S. market; existing products that received approval before the ban remain available. However, the company must pass through the FCC process to introduce new products, which requires an assessment by the Department of Defense or the Department of Homeland Security establishing that there are no national-security risks, along with a justification for using foreign manufacturing and a detailed timeline for expanding manufacturing inside the United States.
In its latest response, TP-Link said it is undergoing the standard approval procedures like other companies and is working to launch a Wi‑Fi 8 lineup for American consumers. The source does not provide a date for a decision on the exemption request, nor do the lawsuits determine whether the states’ claims will be proven in court. Therefore, the impact of the case extends beyond current TP-Link models: it tests the extent to which U.S. authorities rely on component origins and supply chains, as well as companies’ transparency regarding ownership and foreign relationships, when assessing the security of home-networking equipment.