- Four US states sued TP-Link over its security and China claims. The suits cite five flaws in ISP-managed routers, with fixes that ran into 2026.
- Fixing such a flaw is shared work: the vendor builds the update, the ISP delivers it and the customer waits. The source does not say where the time was spent.
- Ask your team who owns firmware updates on ISP-supplied routers, how fast fixes are promised, and until when each model is supported.
When a router flaw is found, three parties share the job. The vendor builds the fix. The ISP delivers it. The customer waits. Each owns one step, and the customer sees none of them. That split sits behind this week's lawsuits against router maker TP-Link.
What the states allege
Four states went to court against TP-Link Systems on October 6: Florida, Iowa, Montana and Nebraska. SecurityWeek reported the filings. Texas brought a similar case in February. The four new suits each rely on state consumer protection laws.
The states say TP-Link oversold its protection. They single out two marketing lines. One says its HomeShield service "covers all security scenarios." The other, used as late as November 2025, promised a "100% safeguard."
The complaints also say some exploited router models cannot update themselves automatically. They add that those models are past their security support.
The suits also dispute how far TP-Link has moved away from China. The states say a large share of its research, development and manufacturing is still based there.
TP-Link rejects all of this. It calls the suits "built on false premises." These are allegations, not findings. No court has ruled.
How the flaws work
To argue that problems persist, the complaints cite five flaws, CVE-2025-30237 through CVE-2025-30241. All sit in Aginet products, TP-Link's range of mesh systems, routers and modems that ISPs manage.
SEC Consult, the firm that found them, published details on Thursday. Its summary: an attacker on the same network could fully take over an affected device, with no login.
The most severe is CVE-2025-30237, an authentication bypass in the router's web server. Someone who can reach the web page can create a top-level administrator account. They can also switch on remote shell access (SSH). No password is needed.
CVE-2025-30241 is a command injection flaw in the same interface. A logged-in attacker can run commands as root, which means total control. CVE-2025-30238 lets a low-privileged user do administrator tasks.
CVE-2025-30239 is a design choice, not a coding slip. Configuration files and backups are locked with fixed keys that depend only on the device model. An attacker with such a file can pull the key from the firmware. They can then read user passwords and Wi-Fi credentials. Depending on setup, they can also read the logins the ISP uses for remote management.
CVE-2025-30240 needs physical access. A specially prepared USB drive can expose the device's whole file system.
Who builds, who delivers, who waits
The timeline shows the split at work. SEC Consult began reporting the flaws in December 2024. In January 2025, TP-Link said the initial issues were fixed. TP-Link disclosed the five flaws in August.
Identifying all affected models took until July 2025, and the rollout of fixes, including custom firmware for ISPs, ran into 2026. The source does not say where the time was spent. It gives no breakdown, so we cannot say how much, if any, came from ISP hand-offs.
The 65 devices include mesh systems, routers, fiber devices and DSL modems. ISP-customized versions are affected too. TP-Link says ISPs distribute the updates. Customers are told to check their device's management page or app. If nothing is offered, they should contact their ISP.
By TP-Link's account, updates come through the ISP, so customers depend on it. SEC Consult held back proof-of-concept exploit code. It worried that many vulnerable devices are still unpatched.
What this means beyond one vendor
The lesson is about ownership, and it is our reading of the case. A security promise on the box says little about who finishes the job after the sale. That matters for any equipment an ISP supplies or manages.
The source covers one vendor and one product line. It does not show that ISP-managed routers as a group patch slowly.
Policy pressure is also building. On October 7, 21 state attorneys general urged the FCC to scrutinize TP-Link. The company wants conditional US approval to sell new router models. That request follows the FCC's March decision to put foreign-made routers on its Covered List.
Questions to put to your team
Start with inventory. Which offices, shops and remote staff connect through ISP-supplied routers or modems? Ask for the make, model and firmware version of each.
Next, ask who is responsible for firmware updates on those devices. If it is the ISP, ask what delivery time it commits to. Ask how you would learn that a fix exists.
Then ask for each model's support end date. The complaints allege that some exploited models no longer get security updates. Finally, treat a phrase like "100% safeguard" as a claim to test, not as evidence.
A router's real security record is not printed on its box. It is how far a fix has to travel, and through how many hands, to reach the device.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: SecurityWeek.





