Policy & Regulation

TP-Link router flaws move into court and FCC fights

Four more U.S. states sued TP-Link on Oct. 6, bringing the total to five, while 21 state attorneys general separately pressed the FCC over the company’s U.S. approval bid. The complaints say TP-Link overstated both router security and its separation from China; TP-Link says it will fight the claims.

The filings point to public firmware flaws, including CVE-2023-50224 and CVE-2025-30237, and to end-of-life models as evidence that the company’s security marketing did not match the product reality. That matters because the bugs are no longer just patch notes for owners; they are now being used as proof in consumer-protection and regulatory arguments about what buyers were told.

For ISPs, resellers, and procurement teams, the exposure now includes approval fights and advertising claims, not only the routers behind the customer edge. If a vendor’s security story depends on firmware that is publicly documented as flawed, the legal and supply-chain fallout can outlast any fix.

3 sources · 20h ago

CVE-2023-50224

NVD KEV

Known exploited · CISA KEV

CVSS 6.5 MEDIUM: tP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. EPSS 16% (97th percentile).

CISA federal remediation date Sep 24 · date passed

CVE-2025-30237

NVD KEV

EPSS 0.3% (23rd percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-10-10

Every edition of this story: TP-Link router flaws move into court and FCC fights