The Florida Office of the Attorney General filed a civil complaint on October 6, 2026 against TP-Link Systems Inc., the Irvine, California networking company, in the Circuit Court of the Tenth Judicial Circuit in Polk County. According to the complaint, the company misled Florida consumers about router security, about its separation from Chinese operations and about the data practices of its apps, in breach of the Florida Deceptive and Unfair Trade Practices Act.

In Short

Florida's state government has taken a router company to court, saying its website and ads promised strong protection from hackers and a clean break from China that the state says the facts do not support. The case affects buyers of a brand that, according to testimony the complaint cites, holds at least 60 percent of the US retail market for home and small-office routers, and the state says some older models still in use no longer get security fixes. These are claims by the state that no judge has decided, so for now the practical change is that TP-Link must answer the allegations in court, where a loss could mean orders to change what it says and to pay money.

Five counts, one defendant

The caption names the Department of Legal Affairs, acting through the Attorney General, as plaintiff and TP-Link Systems Inc. as the only defendant. A California corporation with its headquarters at 10 Mauchly in Irvine, the company is distinct in the filing from TP-Link Technologies Co., Ltd., a Chinese entity that the complaint says is not a party. The document carries an e-filing stamp of 11:41 a.m. on October 6, 2026, and the case number line is blank. It is signed for Attorney General James Uthmeier by Senior Assistant Attorney General Henry Q. Johnson and colleagues, with Culper Law PLLC of Phoenix listed as outside counsel whose admission to the Florida proceeding is marked as forthcoming.

The state brings the case exclusively under Florida law and expressly disclaims any federal claim, according to paragraph 44 of the complaint. It pleads five counts:

  • Count I covers false and deceptive security representations, including the HomeShield service and model-specific claims.
  • Count II covers representations and omissions about corporate separation, the supply chain and manufacturing.
  • Count III covers omissions in data practices and privacy policies.
  • Count IV alleges unfair acts or practices, including the end of security support for models still in homes.
  • Count V alleges unconscionable acts or practices.

The relief sought is broad. The state asks for a permanent injunction under section 501.207(1)(b) of the Florida Statutes, disgorgement of ill-gotten gains, and civil penalties of $10,000 for each willful violation under section 501.2075. A higher figure of $15,000 is sought, according to the prayer for relief, for each willful violation that victimizes a senior citizen or a person with a disability, or that is directed at a servicemember, a servicemember's spouse or dependent child, or a veteran. Attorney's fees, costs and a jury trial are also requested. The complaint alleges on information and belief that members of each protected group bought TP-Link devices, and it pleads that the violations were willful.

Counting is where the exposure could grow. The complaint states that "Each deceptive representation, omission, sale, offer for sale, and advertisement constitutes a separate and independent violation of FDUTPA". Yet the filing offers no estimate of aggregate penalties and no tally of affected consumers, saying only that the company advertised and sold "thousands of devices" in Florida.

The security count starts with HomeShield, a service the complaint describes as built into HomeShield routers and Deco mesh products. TP-Link currently represents, according to the complaint, that HomeShield "covers all security scenarios". An archived version of its website from November 14, 2025 went further, calling it a "100% safeguard" for network security. The state says TP-Link sells these products directly to Floridians through its own online stores, and through a retail list that includes BrandsMart USA, Office Depot, Amazon, Best Buy, Costco, Walmart, Target, Home Depot, Lowe's, Sam's Club and Staples. Six internet service providers operating mainly in Florida - Blue Stream Fiber, Broadstar, Central Florida Broadband, QXC Communications, Summit Broadband and WingNet Communications - are also named as customers. None of these companies is a defendant.

Model-specific copy forms the second layer. The complaint quotes TP-Link advertising for the TL-WR940N ("Easy Setup and Use" and a Tether app feature for "access control"), the Archer C7 (a promotional video telling buyers the router would "future-proof" a home network) and the Archer AX21 ("Refined Password Security" and a "New Level of Cyber Security"). Several of the cited product pages are drawn from archived copies dated October 6, 2022, March 29, 2023, November 14, 2025 and March 31, 2026, which shows how long marketing copy can remain available as evidence after a page is edited.

The vulnerability record behind the claims

The state pairs each claim with a cataloged flaw. The table below summarizes the models named in the complaint, using the figures and dates it gives.

Model or lineFlaw citedDetail given in the complaint
TL-WR940NCVE-2023-50224Exploited by the Quad7 botnet (tracked by Microsoft as CovertNetwork-1658) and by the Russian GRU; no automatic firmware updates; sold through 2024
Archer C7 (v2, v3)Compromised in Quad7 operationsNo automatic firmware updates; also among routers hacked by the GRU, per a Fox News report of June 14, 2026
Archer AX21 (v1 to v3)CVE-2023-1389Unauthenticated command injection; TP-Link said in April 2023 the model had been added to the Mirai botnet arsenal; v1 and v1.20 declared end of life in May 2024
Archer AXE75CVE-2024-53375, CVE-2025-15568Command execution and, in certain scenarios, remote code execution
Archer AX55 (v4)CVE-2026-18167, CVSS 7.7Stack-based buffer overflow in the EasyMesh module, advisory published September 3, 2026
Archer BE800, BE3600, AX75CVE-2026-9254, CVSS 8.7Command injection in parental controls, executing with root privileges, disclosed late August 2026
Tapo C120 and C200 camerasCVE-2026-15315 (CVSS 8.7), CVE-2026-15316 (CVSS 7.1)Authentication bypass and denial of service; reported to TP-Link April 16, 2026, patched August 18, 2026
Aginet ISP-managed lineCVE-2025-30237 to CVE-2025-30241Lead flaw rated CVSS 8.7; missing authorization checks allow login bypass
Omada business ecosystem15 vulnerabilities including CVE-2025-9289Hard-coded cryptographic keys and predictable serial numbers in Zero-Touch Provisioning, disclosed by Forescout in August 2026

Two technical threads run through the complaint. The first is the Quad7 network. Microsoft reported in October 2024, according to the complaint, that CovertNetwork-1658 was built predominantly from compromised TP-Link routers and used for "highly evasive password spray attacks" against think tanks, government organizations, law firms and the defense industrial base, with a Chinese actor tracked as Storm-0940 then using the harvested credentials. The complaint adds that TP-Link itself acknowledged the botnet was "predominantly TP-Link devices".

The second thread is the Russian GRU. The complaint quotes the FBI and NSA as saying the GRU supplies fraudulent DNS answers for specific domains, including Microsoft Outlook Web Access, enabling adversary-in-the-middle attacks "if users navigate through a certificate error warning". That condition matters: in the complaint's own summary, a consumer believes traffic is secure while the GRU views it unencrypted, but the quoted advisory ties the attack to a user clicking past a certificate warning.

Patching is the recurring weak point. The TL-WR940N and several other models do not support automatic firmware updates, so protection depends on a consumer finding and installing a patch by hand. On the AX21, the complaint says a Tether app user received notice of the critical update only as a red dot on a menu. TP-Link no longer issues updates for the AX21 v1 and v1.20, and its end-of-life policy states that it stops "support and maintenance, including security updates". The state also points to a sequence in 2026: in April, TP-Link published a list of affected routers that omitted the TL-WR940N and described all affected products as end of life; in May it acknowledged that the TL-WR940N was affected after all, even though a 2023 security analysis it had cited named that model.

Corporate separation and the Vietnam claim

Count II rests on two statements. In a May 11, 2024 announcement, TP-Link described a restructuring that "encompass[ed] all shareholdings and operational aspects", including legal entities, workforce, research and development, production, marketing and customer service. In a March 5, 2025 statement it said its ownership, management and operations were "entirely different" from those of TP-Link Technologies. Its fact sheet says no government, foreign or domestic, has "access to and control over the design and production of our routers and other devices".

The complaint answers with figures from Bloomberg, which it cites as the source. According to the April 11, 2025 report, the combined Chinese operations employ about 11,000 people against roughly 305 based in the United States; the complaint adds that LinkedIn lists 484 associated members. TP-Link has operational control over at least four facilities in China - a Shenzhen research and development center and manufacturing centers in Shenzhen, Dongguan and Guangqiao - and is building a fifth engineering facility in Chengdu. Asked about an investment of $180 million in Chengdu, a TP-Link spokesperson said only that the company had stopped increasing investment in China, which the complaint treats as short of the separation it announced. The state also cites a former employee's Glassdoor review from June 2026 and a reported social media photograph of representatives of both companies at a Chinese Communist Party event; the filing does not independently verify either.

Official designations form the sharpest part of the record. According to the complaint, the US Department of Defense identified TP-Link Technologies on June 8, 2026 as a Chinese military company operating in the United States under section 1260H of the National Defense Authorization Act for fiscal 2021, with a Federal Register notice following on June 10. Hikvision and Dahua, whose devices the complaint says were compromised in the same Quad7 botnet, appeared on the same list.

The Vietnam claim is narrower and numerical. TP-Link says it builds products for the US market in its own Vietnamese factory and that this "provides another layer of security and governance for the supply chain". The complaint says only 0.5 percent of the components in that plant, by value, are bought in Vietnam, with everything else imported from or through China - a figure it says Bloomberg reported from trade data and TP-Link confirmed. It adds that China State Construction Engineering Corporation, itself designated by the Defense Department, performed recent construction at the site, and cites shipments from Lianzhou Technologies Co., Ltd. to Long Beach, California as recently as January 2026 and from Shanghai in December 2025.

Chinese law and the privacy-policy count

Count III moves from hardware to disclosure. TP-Link's Tether, Deco, Tapo and Kasa Smart apps collect email addresses, location and mobile phone identifiers, and the complaint says that enabling a geofencing smart action lets TP-Link collect precise location. Their privacy policies reserve the right to share data with affiliates to comply with applicable law and to protect the rights of others. The state's theory is that the omission, rather than the wording, is deceptive: none of the policies mentions that Chinese facilities, affiliates and personnel fall under China's 2017 National Intelligence Law.

Article 7 of that law, as quoted in the complaint, requires organizations and citizens to "support, assist, and cooperate with national intelligence efforts in accordance with law". The complaint cites a 2020 Department of Homeland Security advisory describing the law as compelling Chinese entities to turn over data collected abroad and at home. A second regime, the 2021 Regulations on the Management of Security Vulnerabilities in Network Products, requires Chinese providers to report newly found vulnerabilities to the Ministry of Industry and Information Technology within two days. A senior Homeland Security official has said, according to the sources the complaint cites, that China appears to use the rule to preview zero-day flaws before fixes exist. From this the state argues that HomeShield cannot truthfully claim to cover all scenarios, since a later patch does not undo an earlier disclosure to a government.

Pressure that predates the filing

The Florida case follows a run of federal and state steps, several of which the complaint itself lists. A Wall Street Journal report of December 18, 2024 said the Commerce, Defense and Justice departments had opened investigations into TP-Link. A Bloomberg report of October 9, 2025 said federal officials had weighed a ban on sales as an "unacceptable risk". On March 23, 2026 the FCC's Public Safety and Homeland Security Bureau added routers produced in foreign countries to its Covered List, and the complaint adds that TP-Link has since sought conditional approval to sell new models, citing PCMag of April 23, 2026.

The FCC action needs reading with care. According to Baker McKenzie, it applies to the product category rather than to named companies or countries, and it bars approval of new consumer router models absent a conditional approval from the Department of War or the Department of Homeland Security. A Lerman Senter analysis reproduced by JD Supra notes that users are not required to replace routers already authorized. Because of that design, the FCC step does not single out TP-Link by itself.

Within Florida, the Attorney General's office issued an investigative subpoena to TP-Link Systems dated December 2, 2025, signed in the same Senior Assistant Attorney General's name that appears on the complaint, and its press release said the subpoena was not a determination of wrongdoing, according to the Florida Attorney General's office. On February 5, 2026 the office created a unit it calls Consumer Harm from International Nefarious Actors, which according to Cooley is tasked with using the Florida Deceptive and Unfair Trade Practices Act against companies whose data practices may expose residents to foreign exploitation. Texas sued TP-Link on February 17, 2026 under its own deceptive-practices statute, according to Bloomberg Government.

What remains contested

Nothing in the complaint is a finding. It also leans in places on secondary sources - Bloomberg, a Wall Street Journal report, PCMag, a Medium analysis of the Quad7 botnet and a Fox News item - and pleads several facts on information and belief, among them the details of the Flax Typhoon disruption operation and the importer relationships.

Market share is one disputed number. The complaint relies on congressional testimony of March 5, 2025 by Rob Joyce, a former National Security Agency official, that TP-Link holds at least 60 percent of the US retail market for Wi-Fi systems and small-office routers. According to Fox News, which reproduced a TP-Link Systems statement, research from Dell'Oro Group puts the company's share of North American residential Wi-Fi router sales under 10 percent. The two figures may measure different markets, and the complaint does not reconcile them.

On Chinese control, TP-Link's public position in the Texas case was that neither the Chinese government nor the Communist Party holds ownership or control, and that its founder and chief executive, Jeffrey Chao, lives in Irvine and is not a party member, according to Engadget. The company called the Texas allegations without merit, according to BleepingComputer. The complaint contains no TP-Link response, and no company statement on the Florida filing had been located when this article was written.

On the technical side, according to CEPRO, which summarized Check Point Research's analysis of the Camaro Dragon implant that the complaint also cites, the implanted components were firmware agnostic rather than unique to TP-Link. Federal policy has also moved unevenly: Reuters reported in February 2026, according to Yahoo News, that the Trump administration had paused its own proposed ban on TP-Link sales. And a commercial rival has opened a parallel front: according to Tom's Hardware, Netgear filed counterclaims on June 11, 2026 accusing TP-Link of false advertising over its claim to have split entirely from its Chinese parent.

Why the filing matters to marketers

The complaint reads as an inventory of marketing artifacts treated as evidence. Product pages, a promotional video, a retailer badge, app-store listings, privacy policies and a corporate fact sheet each carry a separate allegation. The state cites the "Amazon's Choice" labels on the Archer AX21 v5 and Archer AX55 to underline how prominent those products are, which places marketplace signals alongside brand copy in the record. Archived pages from as early as 2022 are cited for the wording shown at the time.

The disclosure theory is the part with the widest reach beyond routers. Count III does not allege that a privacy policy says anything false; it alleges that generic wording about sharing data with affiliates and complying with law omits a foreign legal obligation. That is the same structure Texas used against Hisense in December 2025, when, as PPC Land reported, the Attorney General secured a temporary restraining order on the day of filing and cited China's National Intelligence Law in a case over automatic content recognition data from smart televisions. The Texas penalty ceiling in that case was $10,000 per violation, rising to $250,000 where conduct targeted consumers aged 65 or older; Florida's comparable figures are $10,000 and $15,000. According to Corporate Compliance Insights, the Texas series of February 2026 used a consumer-protection statute, rather than national security or privacy law, to police companies with alleged Chinese affiliations; the Florida filing follows the same route.

Several features of the case are specific to Florida. The per-advertisement counting rule quoted above attaches penalties to individual ads and sales, not only to campaigns. The protected-class tier reflects the state's older population and its large military and veteran communities, which the complaint stresses. And the retailer list - eleven named chains plus a distributor and six regional internet providers - shows how a brand's distribution footprint is used to establish jurisdiction in Polk County even though none of those sellers is accused of anything.

What a court makes of these theories is untested. A ruling on whether statements such as "100% safeguard" or "covers all security scenarios" are actionable claims or puffery, and whether silence about foreign law can mislead a reasonable consumer, could become a reference point for security and privacy copy well beyond one router maker.

Timeline

  • 1996: TP-Link is founded in Shenzhen, China, by brothers Zhao Jiaxing and Zhao Jianjun, according to the complaint.
  • 2008: The company enters the US market through TP-Link USA.
  • June 27, 2017: China's National Intelligence Law is published; Article 7 requires cooperation with intelligence efforts.
  • 2021: China issues its Regulations on the Management of Security Vulnerabilities in Network Products, with a two-day reporting rule.
  • April 2023: TP-Link says the Archer AX21 has been added to the Mirai botnet arsenal.
  • May 16, 2023: Check Point Research publishes its analysis of the Camaro Dragon router implant.
  • May 11, 2024: TP-Link announces completion of its corporate restructuring.
  • May 2024: TP-Link treats the Archer AX21 v1 and v1.20 as end of life.
  • October 31, 2024: Microsoft reports on Storm-0940 and the covert network built mainly from TP-Link routers.
  • December 18, 2024: The Wall Street Journal reports that three federal departments have opened investigations into TP-Link.
  • March 5, 2025: Rob Joyce testifies before a House select committee; TP-Link issues a same-day statement on the hearing.
  • April 11, 2025: Bloomberg reports the 11,000 versus 305 employee comparison.
  • October 9, 2025: Bloomberg reports that federal officials are weighing action against TP-Link.
  • November 14, 2025: The archived HomeShield page describes the service as a "100% safeguard".
  • December 2, 2025: Florida's Attorney General issues an investigative subpoena to TP-Link Systems, per the state's press release.
  • December 15, 2025: Texas files its Hisense suit over smart TV data and obtains a temporary restraining order.
  • February 17, 2026: Texas sues TP-Link under its deceptive trade practices law.
  • March 23, 2026: The FCC adds routers produced in foreign countries to its Covered List.
  • April 7, 2026: The FBI and NSA publish the alert on Russian GRU exploitation of routers.
  • April 16, 2026: OPSWAT reports the Tapo camera flaws to TP-Link.
  • May 2026: TP-Link acknowledges that the TL-WR940N is affected by CVE-2023-50224.
  • June 8, 2026: The Defense Department identifies TP-Link Technologies as a Chinese military company; the Federal Register notice follows on June 10.
  • August 18, 2026: TP-Link releases the patch for the Tapo camera flaws.
  • September 3, 2026: TP-Link publishes the advisory for CVE-2026-18167 on the Archer AX55.
  • October 6, 2026: Florida files the complaint in Polk County.

Summary

Who: The Florida Office of the Attorney General, Department of Legal Affairs, led by Attorney General James Uthmeier, is the plaintiff. TP-Link Systems Inc., a California corporation based in Irvine, is the only defendant; TP-Link Technologies Co., Ltd. of China is described but not named as a party.

What: A five-count civil complaint under the Florida Deceptive and Unfair Trade Practices Act, covering security representations, corporate separation and Vietnam manufacturing claims, privacy-policy omissions, and unfair and unconscionable practices. The state seeks an injunction, disgorgement, civil penalties of $10,000 or $15,000 per willful violation, fees and a jury trial.

When: The complaint was filed on October 6, 2026, and e-stamped at 11:41 a.m. The conduct alleged runs from archived 2022 product pages through vulnerability disclosures in August and September 2026.

Where: The Circuit Court of the Tenth Judicial Circuit in Polk County, Florida. The complaint cites sales to Florida consumers through TP-Link's own stores, national retailers and regional internet providers.

Why: The state says TP-Link's security, supply-chain and privacy statements misled consumers while its routers were exploited by Chinese state-sponsored actors and the Russian GRU, and while Chinese law exposed its data and vulnerability handling to government access. TP-Link has disputed comparable allegations in Texas, and no court has ruled on the Florida claims.