Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Politics

States Sue TP-Link Over Router Vulnerabilities Tied to Chinese and Russian Hackers

Four Republican attorneys general have filed lawsuits against TP-Link, alleging the company misled consumers about router security and its Chinese connections, exposing U.S. homes to foreign hacking.

Republican attorneys general from Nebraska, Florida, Iowa and Montana have sued TP-Link Systems Inc., accusing the router maker of deceptive marketing about the security of its devices and its links to China. They argue that older models lack firmware updates and default passwords, making them easy targets for Chinese, Russian and even domestic hackers. The Department of Defense labeled TP-Link Technologies a Chinese military company in June, and former NSA cybersecurity director Rob Joyce testified that the firm controls at least 60% of U.S. router sales.

TP-Link contends its products are now manufactured in Vietnam and free of foreign government control, but the states demand clearer consumer warnings or product withdrawals. The lawsuits also cite specific exploits, such as the Russian GRU's use of the TL-WR940N and the Flax Typhoon botnet that compromised other models. The FCC has already barred new foreign-made routers, but the legal action targets devices already in American homes.

Why it matters

Consumers' home networks may be vulnerable to foreign espionage due to insecure routers sold by a major U.S. vendor.

In this story

TP-Linkrouter securityforeign hackersstate lawsuitsfirmware updatesChinese military designationFBI botnetdefault passwords
Get the beta ↗