Skip to content
FRIDAY, OCTOBER 9, 2026

Independently reported.

Tech

Florida Sued TP-Link Over Router Security Claims. The Complaint Names Five CVEs the Marketing Skipped.

The October 6 lawsuit says TP-Link told customers its home routers were 100 percent secure while five specific vulnerabilities, already tied to Chinese and Russian hacking campaigns, sat in products still on store shelves.

By Mara Voss, Technology

· 4 min read · Updated

Close-up of a home Wi-Fi router's antennas and circuit board under cool blue light, no people, no text.
Illustration: Trestlewire

Key Takeaways

  • •Florida Attorney General James Uthmeier sued TP-Link Systems on October 6, 2026, alleging its router marketing misrepresented security and separation from China; Iowa, Montana, and Nebraska filed similar suits the same day.
  • •The complaint names five specific CVEs, including a CVSS 8.7 root-level command injection flaw (CVE-2026-9254) in router lines still on sale, and ties several to Chinese and Russian state-linked hacking infrastructure.
  • •Florida is seeking $10,000 per willful violation and $15,000 per violation involving seniors, disabled residents, or military families under its deceptive trade practices law.
  • •Three sources give three different TP-Link US router market share figures: Circana's 36.6 percent of units, Rob Joyce's congressional estimate of at least 60 percent, and TP-Link's cited Dell'Oro figure of under 10 percent.
  • •TP-Link called the lawsuits baseless through corporate affairs officer Steve Kovsky; a near-identical Texas suit from February 2026, which includes a Netgear counterclaim, is still unresolved.

Florida Attorney General James Uthmeier, who stood up a dedicated unit in February to investigate Chinese ties in consumer products, filed a civil complaint against TP-Link Systems on October 6, and it does not accuse the router maker of vague corporate sins. It names five specific CVEs, attaches them to specific product lines, and argues TP-Link marketed those same products as secure anyway. Iowa, Montana, and Nebraska filed near-identical complaints the same day.

The short answer

Florida sued TP-Link Systems in Polk County circuit court on October 6, joined that day by Iowa, Montana, and Nebraska. The complaint says TP-Link's marketing, including a claim that its HomeShield service is a 100 percent safeguard, contradicts five named CVEs already linked to Chinese and Russian state hacking operations. Florida is seeking $10,000 per willful violation under its deceptive trade practices law. TP-Link calls the case baseless.

What the marketing said

The complaint spends a lot of its length quoting TP-Link back at itself. An archived HomeShield page from November 14, 2025 called the service a 100 percent safeguard. A promotional video for the Archer C7 promised to future-proof a home network. The Archer AX21 shipped under the line New Level of Cyber Security. Nebraska's parallel complaint adds a fifth: a router sold under the name Refined Password Security that state investigators say let an attacker reach root access with no password at all.

What the complaint says happened instead

  • TL-WR940N: CVE-2023-50224, tied to the Quad7 botnet and Russian GRU exploitation, per the complaint.
  • Archer C7: targeted by hacking infrastructure the complaint calls CovertNetwork-1658; the model does not update itself.
  • Archer AX21: CVE-2023-1389, exploited by the Mirai botnet after TP-Link ended support for the model.
  • Archer AX55: CVE-2026-18167, a buffer overflow the complaint rates 7.7 out of 10 on the industry severity scale.
  • Archer BE800, BE3600, and AX75: CVE-2026-9254, a root-level command injection flaw rated 8.7, in models still for sale.

8.7

CVSS severity score for CVE-2026-9254

A root-level command injection flaw the complaint says sits in three router lines TP-Link was still selling when the suit was filed.

The China question

The complaint does not stop at bugs. It argues TP-Link's claimed separation from China is cosmetic rather than real. It cites Bloomberg reporting that counted roughly 11,000 TP-Link employees in China against about 305 in the United States as of April 2025. Research and manufacturing, the filing says, run through at least four facilities in Shenzhen, Dongguan, and Guangqiao, with a fifth engineering site under construction in Chengdu. Final assembly moved to Vietnam, but the complaint puts Vietnamese-sourced components at roughly half a percent of the total by value, with the rest imported from or through China. The Pentagon designated TP-Link Technologies a Chinese military company under the National Defense Authorization Act in June 2026.

Nobody agrees on how big TP-Link even is

Circana's 2024 retail data put TP-Link at 36.6 percent of US router units sold and 31 percent of dollars. Former NSA cybersecurity director Rob Joyce testified to Congress in 2025 that TP-Link controls at least 60 percent of the US retail market for Wi-Fi systems and small-office routers. TP-Link's own cited research, from Dell'Oro Group, puts the company under 10 percent. Three credible-sounding numbers, three different estimates of how big a problem this is for the average router buyer, and the complaint does not resolve which one is right.

“TP-Link sold Floridians the digital front door to their home network while misrepresenting how secure it was, how separated the company was from China, and what could happen to their data.”

James Uthmeier, Florida Attorney General

TP-Link's answer

TP-Link did not stay quiet. Corporate affairs officer Steve Kovsky said in a statement that the coordinated lawsuits are built on false premises and do nothing to advance national security while unfairly penalizing a US company. He said TP-Link's products go through extensive testing with outside security labs, that the company will not share customer network data with foreign governments, and that TP-Link will refute the allegations in court. The company points to a 2024 restructuring it says separated it from its former Chinese parent entirely.

That restructuring is itself contested ground. Florida's complaint quotes a May 2024 TP-Link statement describing the separation as covering all shareholdings and operational aspects, then argues the ongoing Chinese facilities and the roughly 11,000-to-305 employee split show otherwise. Netgear, a competitor, filed a counterclaim in June 2026 in Texas's earlier case against TP-Link, arguing the separation claims themselves amount to false advertising.

This is not a one-state problem

Texas sued TP-Link in February 2026 on similar grounds, which means Florida's filing is the second wave, not the first. The FCC added new authorization hurdles for foreign-made router hardware in March 2026. None of that decides whether Florida's specific CVE claims hold up in a Polk County courtroom, and no ruling exists yet. What the complaint does is turn five years of marketing copy into exhibits, line by line, next to the vulnerability database. Whatever a judge eventually decides about the China allegations, that comparison is now public record.

  • TP-Link
  • Florida Attorney General
  • James Uthmeier
  • router security
  • China ties
  • cybersecurity
  • FDUTPA

About the reporter

Mara Voss

Technology Reporter, Trestlewire

I spent seven years as a product manager at a mid-size SaaS company before I ever wrote a sentence for pay, which means I have sat through more roadmap reviews than most people would tolerate in a lifetime. I watched a scheduling feature get rebranded three times before it shipped, and I watched a launch date slide past four straight quarters while the slide deck stayed exactly the same. That is where the question I still ask every day came from: does this actually ship, or is it a demo.

Read full bio and all stories →