Four state attorneys general sued TP-Link Systems on October 6, bringing to five the number of states now pursuing the Wi-Fi router maker in court over its ties to China. Florida, Iowa, Montana and Nebraska filed separate suits the same day, joining Texas, which sued in February. None of the five cases is a federal national-security action. All five are built on state consumer-protection statutes, the kind normally used against false advertising, because no federal statute currently names TP-Link at all.
Chinese state-sponsored hackers exploited TP-Link routers sitting in American living rooms.
That line belongs to Florida Attorney General James Uthmeier, who filed his 59-page complaint in Polk County, as Ars Technica reported. Florida is seeking civil penalties of $10,000 per willful violation under the Florida Deceptive and Unfair Trade Practices Act, rising to $15,000 when the violation affects a senior, a person with a disability, or a servicemember, plus disgorgement of profits and a permanent injunction, according to the complaint’s text, as detailed by ppc.land. Texas, which sued first, asks for up to $10,000 per violation of its own Deceptive Trade Practices Act, or up to $250,000 per violation where the consumer is 65 or older, per the Texas attorney general’s release. Montana’s attorney general, Austin Knudsen, filed his suit in Lewis and Clark County and separately petitioned the FCC to review TP-Link’s China ties before letting it sell any new router model in the US, according to Montana’s Department of Justice. TP-Link’s corporate affairs officer, Steve Kovsky, called the four October suits coordinated and said they were “built on false premises” that “do nothing to advance national security while unfairly penalizing an industry-leading US company.”
The rule that doesn’t name TP-Link
The states are filling a gap. On March 23, 2026, the FCC’s Public Safety and Homeland Security Bureau added “routers produced in a foreign country” to its Covered List, barring new equipment authorizations for consumer-grade routers made wholly or partly outside the US, per the FCC’s own Covered List page. The rule targets a product category, not a company: it doesn’t force anyone to pull an already-approved router out of a living room, and it exempts any device that gets a time-limited Conditional Approval from the Department of War or the Department of Homeland Security, typically good for about 18 months. Netgear got one on April 14. Eero (Amazon) got one on April 22. Calix, Nokia, Starlink, Asus, Adtran and a growing list of smaller manufacturers followed through the summer.
TP-Link has none of that. The company says it is investing “hundreds of millions of dollars” to bring router manufacturing and R&D onshore in pursuit of an exemption, but as of early October it cannot sell any new Wi-Fi 7 or Wi-Fi 8 router in the US. Its first Wi-Fi 8 model, the Archer 8 Ultra, is on preorder in Europe and Australia; the US launch list leaves it out. Pre-ban models that already cleared FCC certification can still be sold, which is why TP-Link’s gear hasn’t disappeared from shelves even as its newest hardware can’t get in.
Why there’s no ban with TP-Link’s name on it
TP-Link’s problem started well before the Covered List rule. The House Select Committee on the CCP wrote to the Commerce Department in August 2024 asking it to investigate; Commerce, the Justice Department and the Pentagon all opened separate probes into whether TP-Link’s dominance of the router market, combined with its China-based supply chain, amounted to a national-security risk. A company-specific ban looked likely to follow. It didn’t. The White House shelved that plan, according to Reuters reporting cited by 9to5Mac, ahead of a summit between President Trump and China’s Xi Jinping. No Commerce determination under the Information and Communications Technology and Services rules has been issued against TP-Link since. Florida’s complaint explicitly disclaims any federal cause of action, resting entirely on state law — a tell that the people suing TP-Link know the federal case was never finished.
| From | To | How |
|---|---|---|
| Commerce, DOJ, DoD investigate (from 2024) | NSA official testifies: 60% share (House Select Committee, Mar 2025) | |
| NSA official testifies: 60% share (House Select Committee, Mar 2025) | White House shelves company ban (ahead of Trump-Xi summit, reported Feb 2026) | ban drafted, then paused |
| White House shelves company ban (ahead of Trump-Xi summit, reported Feb 2026) | FCC bars new foreign-made routers (Covered List rule, Mar 23 2026; names no company) | generic rule survives |
| White House shelves company ban (ahead of Trump-Xi summit, reported Feb 2026) | Texas sues TP-Link (Feb 2026) | states step in |
| Pentagon lists TP-Link Technologies (Section 1260H, Jun 8 2026) | FL, IA, MT, NE sue TP-Link (Oct 6 2026) | cited as evidence |
| Texas sues TP-Link (Feb 2026) | FL, IA, MT, NE sue TP-Link (Oct 6 2026) | four more follow |
What the five lawsuits allege
The complaints converge on two claims: that TP-Link oversold its security, and that it understated its China ties. On security, the suits cite TP-Link’s HomeShield service, which archived marketing from November 2025 described as a “100% safeguard” covering “all security scenarios.” They name specific end-of-life models still in use, including the TL-WR940N and Archer C7, and specific vulnerabilities: CVE-2023-50224 and CVE-2023-1389, both tied to the botnet Microsoft calls CovertNetwork-1658, and CVE-2025-9377, a command-injection flaw CISA added to its Known Exploited Vulnerabilities catalog in September 2025 with a federal remediation deadline of September 24, 2025, per The Hacker News. Microsoft’s own account of CovertNetwork-1658 is more specific than any of the lawsuits: the botnet held more than 16,000 compromised devices at its peak, averaged around 8,000 active at a time, and drew mostly on TP-Link routers to run low-volume, hard-to-detect password-spray attacks against think tanks, law firms, government bodies and defense contractors on behalf of a China-based actor Microsoft tracks as Storm-0940, according to Microsoft’s October 2024 report. Nebraska’s complaint adds that Russia’s GRU also exploited the same router flaws.
On China ties, the suits dispute TP-Link’s own account of its 2024 corporate split, in which the China-based TP-Link Technologies spun off the US-incorporated TP-Link Systems. Florida’s complaint, citing Bloomberg reporting, puts TP-Link Technologies’ headcount at roughly 11,000 in China against about 305 employees in the US, and says Vietnam-sourced components account for roughly 0.5% of value in routers marketed as “Made in Vietnam,” the rest imported from or through China. Uthmeier’s framing of that gap is blunt: “They also told Floridians they had split from China and that they build US products in Vietnam. That is fiction.” The split got harder to defend in June, when the Pentagon added TP-Link Technologies — the China-based entity, not the US one being sued — to its Section 1260H list of Chinese military companies, finding it “directly affiliated with the PLA” and a contributor to China’s military-civil fusion. The designation technically applies to a different corporate entity than the one named in the state suits, a distinction TP-Link has leaned on and the states have mostly ignored, treating the two companies as one for disclosure purposes.
How big is TP-Link, really
Every one of these cases rests on an unresolved number: how much of the US router market TP-Link actually controls. Rob Joyce, a former NSA cybersecurity director, told the House Select Committee on March 5, 2025, that TP-Link held at least 60% of the US retail market for Wi-Fi systems and SOHO routers, up from about 10% in 2019, in written testimony that Montana’s and Iowa’s complaints both cite directly. TP-Link’s own fact sheet cites Dell’Oro Group data putting its share of North American residential Wi-Fi router sales, including units supplied by ISPs, under 10% in 2024, per TP-Link’s fact sheet. The two numbers are measuring different things — Joyce’s figure is a retail-channel estimate for Wi-Fi systems and SOHO routers specifically; Dell’Oro’s is a broader residential category that includes ISP-bundled hardware, which skews toward other brands. Neither side has reconciled the methodologies, and the state complaints haven’t tried.
TP-Link has disputed the higher figure before. The company’s president told the same committee in March 2025 that “witnesses at the hearing didn’t present a shred of evidence that TP-Link is linked to the Chinese government, and we are not.” In response to the Texas suit, TP-Link said it would “vigorously defend” its reputation, that no Chinese government entity owns or controls the company, its products or user data, and that US user data sits on Amazon Web Services infrastructure. As of this week’s filings, TP-Link had not yet issued a model-by-model response to the specific CVEs or the HomeShield marketing language the four new suits quote.
What happens next depends on two separate, slow-moving processes that have nothing to do with each other on paper but everything to do with each other in practice. The FCC has not granted TP-Link a Conditional Approval, and nothing in the public record suggests one is imminent. Commerce has not issued the ICTS determination that would let the executive branch act against TP-Link by name, and the White House’s reported reluctance to revive that process ahead of trade diplomacy with Beijing hasn’t visibly changed. Five state consumer-protection suits can extract penalties and disclosures; they can’t order a company off store shelves nationwide. Whether that gap gets closed by an FCC exemption decision, a revived Commerce determination, or a sixth state’s lawsuit is the number to watch next.

