By October 8, Florida, Iowa, Nebraska and Montana were reported to have brought consumer-protection cases against TP-Link Systems Inc. Iowa filed its petition on October 6, 2026, in Polk County District Court under the Iowa Consumer Fraud Act. The Iowa Attorney General announced the filing, and the petition names TP-Link Systems Inc. as the defendant.
Iowa’s petition targets router security and updates
Iowa alleges that TP-Link’s HomeShield security claims and marketing for specific routers misled consumers. The petition identifies these models and issues:
- TL-WR940N: The petition identifies CVE-2023-50224 and alleges that Quad7 operators and Russia’s GRU exploited the vulnerability. It also alleges the model lacked automatic firmware updates.
- Archer C7 versions 2 and 3: Iowa alleges these versions were compromised in Quad7 operations and did not support automatic firmware updates.
- Archer AX21 versions 1 through 3: The petition identifies CVE-2023-1389. It separately alleges that AX21 v1 and v1.20 lacked automatic updates by default and had reached end-of-life status in May 2024.
- Archer AXE75: The petition names CVE-2024-53375 and CVE-2025-15568 in connection with this model.
Claims about corporate ties, manufacturing and app data
Iowa alleges that TP-Link’s representations about its separation from China left out continuing corporate and supply-chain links. The petition says TP-Link completed its separation from TP-Link Technologies during 2024. It also alleges that just 0.5% of the components used by value at TP-Link’s Vietnam factory were purchased in Vietnam, with other inputs imported from or through China.
The petition further alleges that TP-Link apps collect information such as email addresses, location and mobile-phone identifiers. It challenges privacy-policy language that permits sharing information with affiliates or to comply with law, arguing that the policies omitted material China-related risks.
TP-Link’s reported response and Iowa’s requested remedies
TP-Link reportedly denied the accusations. Iowa asks the court for injunctions, notices to consumers about end-of-life or actively exploited routers, and disclosure of security-update dates at the point of sale. The petition also requests reimbursement, disgorgement and civil penalties of up to $40,000 per violation, plus up to $5,000 for a violation involving an older individual.