Cybersecurity

TP-Link Faces New U.S. Lawsuits Over Vulnerabilities in Internet Service Provider Routers

Four U.S. states have filed lawsuits against TP-Link Systems, accusing the company of overstating its security promises and failing to adequately disclose its ties to China. The lawsuits coincide with the disclosure of technical details about five vulnerabilities in 65 devices in the Aginet series, some of which could allow complete control of a device.

2026-10-08
4 min read
4 views
certi.news
TP-Link Faces New U.S. Lawsuits Over Vulnerabilities in Internet Service Provider Routers

Florida, Iowa, Montana, and Nebraska filed lawsuits against TP-Link Systems on October 6, accusing the company of misleading consumers about the level of protection provided by its networking devices and of failing to provide sufficient clarity about its ties to China. The lawsuits are based on consumer-protection laws in the four states, following a similar lawsuit filed by Texas in February.

The complaints, which are similar in wording, target marketing claims for the HomeShield service, including that it covers “all security scenarios,” as well as the use of the description “100% protection” through November 2025. The states cite congressional testimony linking the exploitation of TP-Link devices to the Volt Typhoon and Flax Typhoon campaigns, in addition to botnets used by Chinese attackers in password-guessing attacks and attacks carried out by Russian hackers against the company’s devices.

Vulnerabilities Could Grant Complete Control of a Device

In parallel with the lawsuits, SEC Consult published technical details about five vulnerabilities that had been cited in the complaints, identified as CVE-2025-30237 through CVE-2025-30241. The vulnerabilities affect Aginet devices managed by internet service providers, including mesh networking systems, routers, and modem devices.

SEC Consult said the vulnerabilities allow an unauthenticated attacker on the same network to fully compromise a device. The most severe vulnerability, CVE-2025-30237, allows authentication bypass in the web server, creation of a top-level administrator account, and activation of SSH access without credentials. CVE-2025-30238 allows a low-privilege user to execute functions reserved for administrators, while CVE-2025-30241 allows commands to be executed with root privileges after authentication.

CVE-2025-30239 concerns embedded, static encryption keys tied to the device model, which could allow the recovery of passwords and Wi-Fi data, and potentially the remote-management credentials of the service provider when configuration files or backups are obtained. CVE-2025-30240 requires physical access to the device, as a specially prepared USB drive can be used to read the entire file system.

What Changes in Practice for Users of Affected Devices?

TP-Link identified approximately 65 affected devices, including Mesh systems, routers, PON fiber devices, and DSL modems, with the impact extending to versions customized by internet service providers. SEC Consult began notifying the company about the vulnerabilities in December 2024, and TP-Link said in January 2025 that the initial issues had been addressed. However, determining all affected models took until July 2025, while the rollout of fixes, including customized firmware for some service providers, extended into 2026.

TP-Link explains that firmware updates are distributed through internet service providers and advises users to check the device’s management interface or associated application and to contact the provider if no update appears. SEC Consult did not publish proof-of-concept exploit code out of concern that a large number of devices would remain unpatched.

A Broader Dispute Over the U.S. Market

TP-Link denies the accusations and describes the lawsuits as “baseless.” Steve Kovsky, the company’s corporate affairs official, said the company provided regulators with documents showing that its U.S. devices are manufactured in Vietnam and that it is not owned or controlled by a foreign government.

The states also accuse the company of failing to clarify that its Chinese subsidiaries are subject to China’s intelligence law and of failing to disclose Chinese regulations issued in 2021 that require the reporting of newly discovered vulnerabilities. The lawsuits seek court orders, the imposition of civil penalties, and the return of money allegedly collected unlawfully, along with requests for jury trials.

On October 7, Montana’s attorney general joined a coalition of 21 attorneys general in a letter to the Federal Communications Commission (FCC), urging it to scrutinize the company, which is seeking conditional approval to sell new router models in the United States. The developments show that the issue is no longer limited to addressing individual vulnerabilities, but now combines network-device security, supply-chain transparency, marketing claims, and the security assessment of a company seeking to maintain access to the U.S. market.

News source
c
Author

certi.news

In the same category

You may also like

View all news