A new wave of lawsuits has hit TP-Link, a leading router manufacturer, with four more U.S. states joining the growing list of plaintiffs accusing the company of prioritizing profits over security and potentially colluding with Chinese authorities. The latest developments add fuel to an ongoing fire that highlights the critical need for consumers to scrutinize the security and accountability of their IoT device providers.
At the heart of these allegations lies a practice known as cross-domain privilege escalation, where routers are designed to allow administrative access from remote locations via public-facing interfaces. While this feature is intended to facilitate effortless remote management, it also creates a backdoor that malicious actors can exploit to gain unauthorized control over networks. This vulnerability, coupled with the fact that many TP-Link routers contain hardcoded backdoors and hardcoded credentials for support personnel, raises concerns about the company’s commitment to security.
The lawsuits filed by these additional states join a chorus of similar complaints from other U.S. jurisdictions, as well as Canada and the European Union, all claiming that TP-Link has been aware of these vulnerabilities for years but has chosen not to address them adequately. The allegations also point out that TP-Link has maintained close ties with Chinese authorities, sparking fears that routers could be used as tools for state-sponsored espionage or surveillance.
The security community is particularly concerned about the impact of these vulnerabilities on critical infrastructure and sensitive networks. As more devices become connected to the internet of things (IoT), the potential attack surface grows exponentially, making it increasingly important for manufacturers to prioritize security-by-design principles from the outset. In this context, TP-Link’s alleged negligence raises red flags, not only about their own products but also about the broader industry’s willingness to put profits above people.
As we continue to navigate an ever-more complex digital landscape, these lawsuits serve as a stark reminder of the need for accountability and transparency in the tech sector. Consumers must stay vigilant when choosing IoT devices, scrutinizing manufacturers’ track records on security, data protection, and corporate governance. This means doing your research, reading reviews from multiple sources, and being wary of low-cost products that may seem too good to be true.
Ultimately, this story serves as a wake-up call for all stakeholders: manufacturers must prioritize security above profits; policymakers must implement stricter regulations and enforcement mechanisms; and consumers must demand more from their device providers. Only through collective action can we build a safer, more trustworthy digital ecosystem where our rights are protected and our networks are secure.
Source: The Hacker News — 2026-10-09