Four more U.S. states have sued TP-Link Systems, saying the router maker misled buyers about security and its separation from China, according to The Hacker News. For a household, the immediate issue is practical: if your router is old, no longer getting fixes, or still using risky settings, it can become an easy target even if your internet seems to work normally.
What happened
Florida, Iowa, Montana and Nebraska filed lawsuits on October 6, bringing the total number of state suits against TP-Link to five. Texas filed a separate suit in February, according to The Hacker News.
The states claim TP-Link advertised router security it did not deliver and overstated how separate TP-Link Systems is from TP-Link Technologies in China. TP-Link denies the claims and says it will fight the lawsuits. The company also said it is an independent U.S. company and does not share customer network data with foreign governments or unauthorized third parties.
The complaints do not all make the same claims in the same way. The Hacker News reports that the Florida, Montana and Nebraska complaints do not allege the Chinese government has obtained customer data through TP-Link; they describe that as a risk under Chinese law. Iowa’s announcement used stronger wording, but also described access as something that could happen.
The story also points to real router security problems. Three complaints cite five flaws in TP-Link devices supplied by internet providers. Researchers published technical details on October 8, and fixes exist, but they reach customers through their ISP. The complaints also mention two versions of the Archer AX21 that TP-Link says reached end of life in May 2024 and no longer receive updates.
Who is affected
This matters most to U.S. households and small offices using TP-Link routers, especially older models, ISP-provided TP-Link equipment, or routers that have not been updated in a long time. The full list of affected ISP-supplied models was not disclosed in the provided source text.
People who use TP-Link’s Tether, Tapo, Deco or Kasa Smart apps should also pay attention. According to the complaints summarized by The Hacker News, those apps collect information such as email addresses, location and phone identifiers. The lawsuits frame that data collection as part of their privacy and China-risk arguments, but the source does not say customer data has been taken by China.
What to do now
- Check your router model and support status. Look at the label on the router or open the router’s app or admin page. If you have a TP-Link Archer AX21, check the exact hardware version and whether TP-Link still supports it. If your model is end-of-life, plan to replace it instead of waiting for security fixes that may never arrive.
If your router is out of support, CyberSec24 recommends replacing it with a currently supported model from another brand that still receives security updates.
Update router firmware today. In the TP-Link app or router admin page, look for firmware update, system update or online upgrade. If your router came from your internet provider, check the provider’s app or support page, because The Hacker News says fixes for the cited ISP-supplied flaws are delivered through the ISP.
Turn off risky remote access. Disable remote management unless you truly need it. Also turn off WPS and review UPnP. These settings can make attacks easier if a router has a flaw. CyberSec24’s guide to router settings to disable explains what to look for.
Change the router admin password. Use a long, unique password that is not used for email, banking or shopping accounts. If your router app supports two-factor authentication, turn it on.
Watch for strange network behavior. Unexpected slowdowns, unknown devices, changed DNS settings or router settings you did not change can be warning signs. If you are unsure, use CyberSec24’s checklist on how to tell if your router is hacked.
How to protect your home network
A lawsuit is not the same as proof that your router is compromised. The safer approach is to make sure your network does not depend on an unsupported box. Keep firmware current, separate smart-home devices on guest WiFi when possible, and replace routers that no longer get fixes. For a broader checklist, see our home network security guide.
Sources
Written by the CyberSec24 news desk with AI assistance, from the sources above. Spot an error? Tell us and we'll correct it.
