Wi-Fi routers sitting in Americans home may be ones foreign hackers already know how to get into, a new lawsuit alleges.
Republican attorneys general in Nebraska, Florida, Iowa and Montana sued TP-Link Systems Inc. on Tuesday, accusing the company of misleading consumers about its routers’ security and its ties to China, according to the lawsuits. The Federal Communications Commission (FCC) blocked new foreign-made routers in March, but its order does not address devices already in use.
“Some of these older routers can be easily exploited by other foreign intelligence agencies,” Republican Nebraska Attorney General Mike Hilgers told the Daily Caller News Foundation.
He urged Nebraskans to check whether their router is “past the time where it’s being supported, where there’s not new updates, or they can’t get new firmware.”
Owners should learn the risks, install any available firmware updates and replace default passwords, Hilgers said.
The Department of Defense designated TP-Link Technologies a Chinese military company in June. TP-Link and TP-Link Technologies have about 11,000 workers in China, but only around 305 in the U.S., Bloomberg reported.
TP-Link told customers its ties to China “have been severed,” Hilgers said in a statement.
“In truth, TP-Link’s products and systems still have strong connections to China, and its supply chain continues to be intertwined with China’s state-sponsored technology ecosystem,” he said.
TP-Link controls “at least 60%” of home and small-office routers sold in U.S. stores, according to former National Security Agency (NSA) cybersecurity director Rob Joyce’s March 2025 testimony before Congress. The company said it severed ties to its Chinese predecessor, TP-Link Technologies, in 2024. (RELATED: China Just Made Great Leap Forward In AI Race With US)
TP-Link referred the DCNF to a Tuesday press release when asked for comment.
“The coordinated lawsuits are built on false premises,” TP-Link corporate affairs officer Steve Kovsky said in the press release.”They do nothing to advance national security while unfairly penalizing an industry-leading U.S. company.”
“We look forward to refuting these baseless allegations in court,” Kovsky added.
The California-based company said it spent months giving state regulators records showing its U.S. routers are made in Vietnam, and no foreign government owns or controls it.
Hilgers said the state would welcome TP-Link pulling the routers from shelves, but at a minimum wants the company to warn buyers.
“If you have these kinds of products that have known security loopholes and flaws that allow hackers and others to be able to reach the sensitive information of Nebraskans, then you should tell people that,” he told the DCNF.
The threat goes beyond China, according to Hilgers. “Given the weakness in the … security infrastructure of these routers, others, including foreign militaries, but even hackers in the United States, can more easily exploit these actual routers,” he said.
Russia’s military intelligence agency found an exploit in TP-Link’s TL-WR940N router to spy on users’ web traffic, the FBI warned in April. TP-Link sold the model through 2024, according to the Nebraska lawsuit.
TP-Link said its Archer C7 provided “secure Wi-Fi access for guests sharing your home or office network” in 2013, but two versions of the product were hijacked by a network known as Quad7, the lawsuits allege.
The router company’s Archer AX21 model was advertised as offering “refined password security,” in 2022. However, Chinese state-link hackers known as Flax Typhoon exploited a flaw, disclosed in 2023, that let attackers take control of the router without a password, according to the state complaints.
The FBI eventually broke up Flax Typhoon’s botnet by wiping thousands of infected routers, according to the Iowa complaint.
“A router is the digital front door to a Florida family’s home,” Republican Florida Attorney General James Uthmeier said in a statement to the DCNF. “TP-Link told consumers those routers were secure, and that the company had split from China and built U.S. products in Vietnam. Those claims are not true.”
Vietnamese suppliers account for half of one percent of the parts, by value, used at the plant, according to Bloomberg reporting cited in the lawsuits.
“As a result of their nefarious practices, millions of Americans have unknowingly invited a foreign adversary into their living rooms and put their personal information at risk,” Republican Montana Attorney General Austin Knudsen said in a statement to the DCNF.
“Iowans’ sensitive data and our national security is at risk because of TP-Link and their connection to the communist Chinese government,” Republican Iowa Attorney General Brenna Bird said in a statement to the DCNF. “It’s time to hold China and China-backed companies accountable,” Bird added.
The FCC added foreign-made routers to its Covered List of restricted products in March.









