---
title: "Four More States Sue TP-Link as Its Routers Stay Locked Out of the US Market"
description: "Florida, Iowa, Montana and Nebraska joined Texas in suing over China ties, while the FCC still withholds approval for new TP-Link hardware"
author: "Luis Goa"
published: 2026-10-07T19:53:42Z
modified: 2026-10-08T06:01:14Z
url: https://rews.cc/a/four-more-states-sue-tp-link-as-its-routers-stay-locked-out--5f01f1
language: en
tags: ["router-ban", "fcc", "security", "china", "sue", "tech", "us"]
publisher: "Rews (https://rews.cc)"
---

# Four More States Sue TP-Link as Its Routers Stay Locked Out of the US Market

*Florida, Iowa, Montana and Nebraska joined Texas in suing over China ties, while the FCC still withholds approval for new TP-Link hardware*

By Luis Goa · October 7, 2026 · https://rews.cc/a/four-more-states-sue-tp-link-as-its-routers-stay-locked-out--5f01f1

## In brief

- Florida, Iowa, Montana and Nebraska sued TP-Link on Oct. 6, 2026, joining Texas’s February suit
- The suits allege TP-Link overstated router security and understated its China ties, under state consumer law
- TP-Link still lacks the FCC exemption that Netgear, Eero, Asus, Calix, Nokia and Starlink got since March 2026
- A White House plan for a TP-Link-specific federal ban was reportedly shelved ahead of a Trump-Xi summit
- The Pentagon added TP-Link’s China-based entity to its Chinese military companies list in June 2026

Four state attorneys general sued TP-Link Systems on October 6, bringing to five the number of states now pursuing the Wi-Fi router maker in court over its ties to China. Florida, Iowa, Montana and Nebraska filed separate suits the same day, joining Texas, which sued in February. None of the five cases is a federal national-security action. All five are built on state consumer-protection statutes, the kind normally used against false advertising, because no federal statute currently names TP-Link at all.

> Chinese state-sponsored hackers exploited TP-Link routers sitting in American living rooms.

That line belongs to Florida Attorney General James Uthmeier, who filed his 59-page complaint in Polk County, as [Ars Technica reported](https://arstechnica.com/tech-policy/2026/10/florida-sues-tp-link-claiming-it-hides-router-security-risks-and-links-to-china/). Florida is seeking civil penalties of $10,000 per willful violation under the Florida Deceptive and Unfair Trade Practices Act, rising to $15,000 when the violation affects a senior, a person with a disability, or a servicemember, plus disgorgement of profits and a permanent injunction, according to the complaint’s text, as detailed by [ppc.land](https://ppc.land/florida-sues-tp-link-seeking-10-000-per-willful-violation/). Texas, which sued first, asks for up to $10,000 per violation of its own Deceptive Trade Practices Act, or up to $250,000 per violation where the consumer is 65 or older, per [the Texas attorney general’s release](https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-sues-tp-link-allowing-ccp-access-americans-devices-first-several-lawsuits). Montana’s attorney general, Austin Knudsen, filed his suit in Lewis and Clark County and separately petitioned the FCC to review TP-Link’s China ties before letting it sell any new router model in the US, according to [Montana’s Department of Justice](https://dojmt.gov/attorney-general-knudsen-files-lawsuit-against-china-founded-tech-company-tp-link/). TP-Link’s corporate affairs officer, Steve Kovsky, called the four October suits coordinated and said they were “built on false premises” that “do nothing to advance national security while unfairly penalizing an industry-leading US company.”

## The rule that doesn’t name TP-Link

The states are filling a gap. On March 23, 2026, the FCC’s Public Safety and Homeland Security Bureau added “routers produced in a foreign country” to its Covered List, barring new equipment authorizations for consumer-grade routers made wholly or partly outside the US, per [the FCC’s own Covered List page](https://www.fcc.gov/supplychain/coveredlist). The rule targets a product category, not a company: it doesn’t force anyone to pull an already-approved router out of a living room, and it exempts any device that gets a time-limited Conditional Approval from the Department of War or the Department of Homeland Security, typically good for about 18 months. Netgear got one on April 14. Eero (Amazon) got one on April 22. Calix, Nokia, Starlink, Asus, Adtran and a growing list of smaller manufacturers followed through the summer.

TP-Link has none of that. The company says it is investing “hundreds of millions of dollars” to bring router manufacturing and R&D onshore in pursuit of an exemption, but as of early October it cannot sell any new Wi-Fi 7 or Wi-Fi 8 router in the US. Its first Wi-Fi 8 model, the Archer 8 Ultra, is on preorder in Europe and Australia; the US launch list leaves it out. Pre-ban models that already cleared FCC certification can still be sold, which is why TP-Link’s gear hasn’t disappeared from shelves even as its newest hardware can’t get in.

## Why there’s no ban with TP-Link’s name on it

TP-Link’s problem started well before the Covered List rule. The House Select Committee on the CCP wrote to the Commerce Department in August 2024 asking it to investigate; Commerce, the Justice Department and the Pentagon all opened separate probes into whether TP-Link’s dominance of the router market, combined with its China-based supply chain, amounted to a national-security risk. A company-specific ban looked likely to follow. It didn’t. The White House shelved that plan, according to Reuters reporting cited by [9to5Mac](https://9to5mac.com/2026/02/18/federal-ban-on-tp-link-routers-shelved-but-texas-fights-on/), ahead of a summit between President Trump and China’s Xi Jinping. No Commerce determination under the Information and Communications Technology and Services rules has been issued against TP-Link since. Florida’s complaint explicitly disclaims any federal cause of action, resting entirely on state law — a tell that the people suing TP-Link know the federal case was never finished.

**A federal ban that stalled, and the gap it left** How the TP-Link case moved from Congress to statehouses

| From | To | How |
| --- | --- | --- |
| Commerce, DOJ, DoD investigate *(from 2024)* | NSA official testifies: 60% share *(House Select Committee, Mar 2025)* |  |
| NSA official testifies: 60% share *(House Select Committee, Mar 2025)* | White House shelves company ban *(ahead of Trump-Xi summit, reported Feb 2026)* | ban drafted, then paused |
| White House shelves company ban *(ahead of Trump-Xi summit, reported Feb 2026)* | FCC bars new foreign-made routers *(Covered List rule, Mar 23 2026; names no company)* | generic rule survives |
| White House shelves company ban *(ahead of Trump-Xi summit, reported Feb 2026)* | Texas sues TP-Link *(Feb 2026)* | states step in |
| Pentagon lists TP-Link Technologies *(Section 1260H, Jun 8 2026)* | FL, IA, MT, NE sue TP-Link *(Oct 6 2026)* | cited as evidence |
| Texas sues TP-Link *(Feb 2026)* | FL, IA, MT, NE sue TP-Link *(Oct 6 2026)* | four more follow |

Based on [State attorney general filings; Pentagon; FCC](https://media.defense.gov/2026/Jun/08/2003945537/-1/-1/1/ENTITIES-IDENTIFIED-AS-CHINESE-MILITARY-COMPANIES-OPERATING-IN-THE-UNITED-STATES-IN-ACCORDANCE-WITH-SECTION-1260H.PDF)

## What the five lawsuits allege

The complaints converge on two claims: that TP-Link oversold its security, and that it understated its China ties. On security, the suits cite TP-Link’s HomeShield service, which archived marketing from November 2025 described as a “100% safeguard” covering “all security scenarios.” They name specific end-of-life models still in use, including the TL-WR940N and Archer C7, and specific vulnerabilities: CVE-2023-50224 and CVE-2023-1389, both tied to the botnet Microsoft calls CovertNetwork-1658, and CVE-2025-9377, a command-injection flaw CISA added to its Known Exploited Vulnerabilities catalog in September 2025 with a federal remediation deadline of September 24, 2025, per [The Hacker News](https://thehackernews.com/2025/09/cisa-flags-tp-link-router-flaws-cve.html). Microsoft’s own account of CovertNetwork-1658 is more specific than any of the lawsuits: the botnet held more than 16,000 compromised devices at its peak, averaged around 8,000 active at a time, and drew mostly on TP-Link routers to run low-volume, hard-to-detect password-spray attacks against think tanks, law firms, government bodies and defense contractors on behalf of a China-based actor Microsoft tracks as Storm-0940, according to [Microsoft’s October 2024 report](https://www.microsoft.com/en-us/security/blog/2024/10/31/chinese-threat-actor-storm-0940-uses-credentials-from-password-spray-attacks-from-a-covert-network/). Nebraska’s complaint adds that Russia’s GRU also exploited the same router flaws.

On China ties, the suits dispute TP-Link’s own account of its 2024 corporate split, in which the China-based TP-Link Technologies spun off the US-incorporated TP-Link Systems. Florida’s complaint, citing Bloomberg reporting, puts TP-Link Technologies’ headcount at roughly 11,000 in China against about 305 employees in the US, and says Vietnam-sourced components account for roughly 0.5% of value in routers marketed as “Made in Vietnam,” the rest imported from or through China. Uthmeier’s framing of that gap is blunt: “They also told Floridians they had split from China and that they build US products in Vietnam. That is fiction.” The split got harder to defend in June, when the Pentagon added TP-Link Technologies — the China-based entity, not the US one being sued — to its Section 1260H list of Chinese military companies, finding it “directly affiliated with the PLA” and a contributor to China’s military-civil fusion. The designation technically applies to a different corporate entity than the one named in the state suits, a distinction TP-Link has leaned on and the states have mostly ignored, treating the two companies as one for disclosure purposes.

## How big is TP-Link, really

Every one of these cases rests on an unresolved number: how much of the US router market TP-Link actually controls. Rob Joyce, a former NSA cybersecurity director, told the House Select Committee on March 5, 2025, that TP-Link held at least 60% of the US retail market for Wi-Fi systems and SOHO routers, up from about 10% in 2019, in [written testimony](https://docs.house.gov/meetings/ZS/ZS00/20250305/117983/HHRG-119-ZS00-Wstate-JoyceR-20250305.pdf) that Montana’s and Iowa’s complaints both cite directly. TP-Link’s own fact sheet cites Dell’Oro Group data putting its share of North American residential Wi-Fi router sales, including units supplied by ISPs, under 10% in 2024, per [TP-Link’s fact sheet](https://www.tp-link.com/us/landing/fact-sheet/). The two numbers are measuring different things — Joyce’s figure is a retail-channel estimate for Wi-Fi systems and SOHO routers specifically; Dell’Oro’s is a broader residential category that includes ISP-bundled hardware, which skews toward other brands. Neither side has reconciled the methodologies, and the state complaints haven’t tried.

TP-Link has disputed the higher figure before. The company’s president told the same committee in March 2025 that “witnesses at the hearing didn’t present a shred of evidence that TP-Link is linked to the Chinese government, and we are not.” In response to the Texas suit, TP-Link said it would “vigorously defend” its reputation, that no Chinese government entity owns or controls the company, its products or user data, and that US user data sits on Amazon Web Services infrastructure. As of this week’s filings, TP-Link had not yet issued a model-by-model response to the specific CVEs or the HomeShield marketing language the four new suits quote.

What happens next depends on two separate, slow-moving processes that have nothing to do with each other on paper but everything to do with each other in practice. The FCC has not granted TP-Link a Conditional Approval, and nothing in the public record suggests one is imminent. Commerce has not issued the ICTS determination that would let the executive branch act against TP-Link by name, and the White House’s reported reluctance to revive that process ahead of trade diplomacy with Beijing hasn’t visibly changed. Five state consumer-protection suits can extract penalties and disclosures; they can’t order a company off store shelves nationwide. Whether that gap gets closed by an FCC exemption decision, a revived Commerce determination, or a sixth state’s lawsuit is the number to watch next.

## See also

- [Iowa v. TP-Link Systems Inc. — full petition](https://www.iowaattorneygeneral.gov/media/cms/261006_Iowa_v_TPLink_Petition_62BE0B0B82A83.pdf) — iowaattorneygeneral.gov · The complete Oct. 6 Iowa complaint, with CVE and GRU allegations
- [TP-Link Systems Inc. rebuts House Select Committee testimony](https://www.tp-link.com/us/press/news/21656/) — tp-link.com · Company's point-by-point response to the 60% market-share claim
- [FCC order granting Starlink routers Conditional Approval](https://docs.fcc.gov/public/attachments/DA-26-775A1.pdf) — docs.fcc.gov · Shows how the Covered List exemption process works in practice
- [Four States Sue TP-Link Over China Connections](https://www.theepochtimes.com/us/four-states-sue-tp-link-over-china-connections-6100789) — theepochtimes.com · Carries direct quotes from Iowa's and Nebraska's attorneys general
