Texas Attorney General Ken Paxton filed a lawsuit against TP-Link Systems Inc., alleging the company deceptively marketed its networking and smart-home devices as secure and privacy-protective while the products were allegedly exposed to exploitation by China-linked state-sponsored actors. The complaint also asserts TP-Link misled consumers about product origin—promoting “Made in Vietnam” labeling while claiming manufacturing and development are dominated by China-based subsidiaries and supply chains, with Vietnam facilities described as performing largely final assembly.
Texas further argues that TP-Link’s China-linked supply chain and alleged affiliations create national-security risk, including the possibility of compelled cooperation under Chinese data and intelligence laws. The state cited prior public reporting and research— including a May 2023 Check Point Research report tying Camaro Dragon activity to exploitation of TP-Link firmware vulnerabilities—as part of its rationale that the devices have been leveraged in campaigns targeting U.S. interests. TP-Link rejected the allegations, calling the lawsuit “without merit,” and stated it is an independent American company with core operations and infrastructure located in the U.S.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
After the lawsuit was announced, TP-Link said the claims were meritless and denied Chinese government or CCP control over the company or user data. It said core operations are in the United States and U.S. user data is stored on AWS infrastructure.
On February 17, 2026, Texas Attorney General Ken Paxton announced a lawsuit against TP-Link Systems alleging deceptive claims about device security, privacy, and 'Made in Vietnam' manufacturing. The suit also alleges risks from China-linked supply chains and seeks penalties, injunctive relief, corrective disclosures, and limits on data collection without informed consent.
Reporting in late 2025 said the U.S. government had considered a sales ban or other federal restrictions on TP-Link routers on national security grounds. Multiple agencies were said to be scrutinizing the company and its products.
Texas opened an investigation into TP-Link in October, according to later reporting on the lawsuit. The probe preceded the state's consumer-protection action over alleged security, privacy, and country-of-origin misrepresentations.
A remote command execution vulnerability, CVE-2025-9377, affecting end-of-life TP-Link routers was disclosed in August 2025. Texas later cited the flaw as evidence that TP-Link continued marketing products as secure despite known security issues.
Last year, CISA disclosed two TP-Link router vulnerabilities that were being actively exploited. The disclosures intensified federal scrutiny of the vendor's security posture.
TP-Link has said it became distinct from China-based TP-Link Technologies following a corporate split in October 2024. The company cited this separation in response to later allegations about Chinese control and affiliations.
In October 2024, Microsoft reported that a large credential-theft botnet tracked as Quad7/CovertNetwork-1658/xlogin was leveraging TP-Link routers. This added to U.S. concern that TP-Link devices were being abused in cyber operations.
A May 2023 Check Point Research report said the Chinese state-sponsored group Camaro Dragon exploited activity enabled by TP-Link firmware vulnerabilities. The report later became part of Texas's case that TP-Link devices were used in PRC-linked hacking campaigns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcebleepingcomputer.com
Open sourcebankinfosecurity.com
Open sourcego.theregister.com
Open sourcegovinfosecurity.com
Open sourcetherecord.media
Open sourcetexasattorneygeneral.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.