TP-Link cannot sell its newest routers in the US without an exemption from a Federal Communications Commission ban, and it is also being sued by four states over alleged security risks and links to China.
Key takeaways
- Ars Technica reports that TP-Link cannot sell its latest router models in the US because they are covered by an FCC ban and the company has not yet received an exemption.
- Florida has sued TP-Link, alleging that the company hides security risks in its routers and plays down its links to China, according to Ars Technica.
- Ars Technica says Florida is one of four US states taking legal action against the router maker, though not every detail of each case is publicly clear.
- The FCC controls which radio-emitting devices can be sold in the US through its equipment authorisation process, so a block at that stage can keep new products off the market.
- Routers are a common target of security concern because they sit between home or office networks and the wider internet.
What is happening to TP-Link in the United States?
TP-Link is one of the best-known brands of consumer networking equipment, including Wi-Fi routers, mesh systems and range extenders. Ars Technica reports that the company is now under pressure from federal and state authorities at the same time.
At federal level, the problem is a ban imposed by the Federal Communications Commission. According to Ars Technica, TP-Link cannot sell its newest routers in the US and still needs an exemption from the FCC before it can. The source does not say how long such an exemption might take, what conditions might come with it, or whether one will be granted.
At state level, Ars Technica reports that Florida has filed a lawsuit claiming that TP-Link hides security risks in its routers and its connections to China. Florida is described as one of four states that have now sued the company. The source material used here does not name the other three states, give the exact legal claims in each case, or say what remedies they are seeking.
Why is this in the news now?
The story has come back into the headlines because of the Florida lawsuit, which adds to a growing list of state actions. Ars Technica presents it as part of a pattern: the company’s difficulties in the US are building up rather than being settled.
Together, the federal ban and the state lawsuits mean TP-Link is dealing with two separate kinds of pressure. One limits what it can bring to market. The other examines how it has described its products and corporate ties to customers. The two processes are different, and a result in one does not necessarily decide the other.
What background does a newcomer need?
Most electronic devices that send or receive radio signals, including Wi-Fi routers, need approval from the FCC before they can legally be marketed in the US. This process is called equipment authorisation. It has mainly been a technical check that a device stays within permitted radio limits and does not cause harmful interference.
Over the past several years, US policy has increasingly used this process for national security purposes as well. Lawmakers and regulators have created mechanisms that let the FCC refuse authorisation to equipment judged to pose an unacceptable risk to US networks or users. The best-known earlier examples involved large Chinese telecoms equipment makers, whose new products were effectively shut out of the US market through this route.
Routers attract particular attention because of where they sit in a network. Every device in a home or small office usually sends its traffic through the router. A router with a serious flaw, or with firmware that could be changed in a harmful way, may expose everything connected to it. Security researchers have long warned that consumer routers are often left running outdated software, which makes them attractive targets for attackers who want to build networks of compromised devices.
TP-Link was founded in China. In recent years it has reorganised its business, and its US operation presents itself as a separate, US-based company. Whether that separation is enough to answer regulators’ concerns is at the centre of the dispute, and the state lawsuits reported by Ars Technica appear to question how TP-Link has described those links.
Who is affected, and how?
Consumers who already own TP-Link equipment. The source material does not say the FCC ban affects devices that have already been sold. In earlier cases, restrictions of this kind have usually targeted new authorisations rather than equipment people already own. Owners should still pay attention to any official guidance, particularly about firmware updates and support.
People shopping for a new router. If TP-Link’s newest models cannot be sold in the US, buyers there will have fewer choices from that brand. Older, already-authorised models may stay on sale, but the source does not confirm this either way.
Retailers and internet service providers. Shops and broadband providers that stock or hand out TP-Link equipment may need to rethink their product ranges. How they will respond is not known.
TP-Link itself. The company faces lost sales of new products, legal costs and possible damage to its reputation. The outcome of the state lawsuits could bring financial penalties or other orders, but the source does not say what is being sought.
Competitors. Other router makers may gain market share if TP-Link’s new models stay off shelves, although no figures are available.
Where do informed people disagree?
The debate around cases like this tends to divide along several lines.
Supporters of tougher measures argue that the risk from networking hardware tied, even indirectly, to a strategic rival is too serious to leave to the market. They point to the central position of routers in home networks and to the difficulty of checking complex firmware for hidden weaknesses. From this point of view, acting early is better than reacting after a large-scale compromise.
Critics raise different concerns. Some argue that security weaknesses are common across the whole consumer router industry, whatever the manufacturer’s country of origin, and that singling out one company does little to fix the wider problem. Others warn that national security tools can be used too broadly, reducing competition and raising prices without clear public evidence of wrongdoing. Companies in TP-Link’s position typically say they meet security standards and that their corporate structure keeps them independent of foreign governments. TP-Link’s specific response to the Florida lawsuit is not included in the source material.
There is also a procedural question: how much evidence should regulators and states have to show before restricting a product, and how much of that evidence should be made public. Classified assessments can be hard to challenge or check from outside.
What are the practical implications?
For households, the immediate practical advice is the same as for any router, whatever the brand:
- Keep firmware up to date, and turn on automatic updates if the device supports them.
- Change default administrator passwords.
- Turn off remote management features that are not needed.
- Replace devices that no longer receive security updates from their manufacturer.
Nothing in the source material says owners of existing TP-Link routers must stop using them. Anyone worried should look for official notices from the FCC or their state’s consumer protection authority rather than relying on rumour.
For businesses that buy networking equipment in bulk, the case shows that regulatory risk is now part of choosing a supplier. A product line that is available today may become hard to buy or replace if the manufacturer runs into federal restrictions.
For the wider technology industry, the case suggests that the US is willing to use equipment authorisation and consumer protection law together, at both federal and state level, to deal with concerns about foreign-linked hardware.
What should readers watch next?
Several developments will shape what happens next:
- The FCC exemption. Whether TP-Link gets an exemption for its newest routers, and on what terms, will decide whether those products reach US shelves.
- The four state lawsuits. Court filings, responses from TP-Link and any settlements will show how strong the states’ claims are and what they want.
- Other states. Whether more states bring their own cases is not known.
- Guidance for existing owners. Any official statement on support, updates or continued use of current devices would directly affect consumers.
- Wider policy. How regulators treat other foreign-linked networking brands will show whether this is a single case or the start of a broader approach.
Frequently asked questions
Can TP-Link sell routers in the US right now?
Ars Technica reports that TP-Link cannot sell its latest router models in the US because they fall under an FCC ban, and the company still needs an exemption. The source does not say whether older models that were approved earlier are affected, so buyers should check current retailer listings and any official FCC notices for up-to-date information on specific products.
Do I need to throw away my TP-Link router?
The source material does not say existing owners must stop using their TP-Link routers. In previous cases, FCC restrictions have usually applied to new product authorisations rather than equipment already in homes. The sensible step for any router owner is to keep firmware updated, change default passwords and replace devices that no longer receive security updates from the manufacturer.
Why did Florida sue TP-Link?
According to Ars Technica, Florida’s lawsuit claims that TP-Link hides security risks in its routers and plays down its links to China. The full details of the legal claims, the evidence offered and the remedies Florida is seeking are not included in the source material. TP-Link’s response to the lawsuit is also not known from the information available here.
Which states are suing TP-Link?
Ars Technica reports that four US states have taken legal action against TP-Link, and Florida is one of them. The source material used for this article does not name the other three states or describe how their cases differ. Readers who want the full list should check official announcements from state attorneys general or court records.
What is FCC equipment authorisation?
Equipment authorisation is the process the Federal Communications Commission uses to approve devices that emit radio signals, such as Wi-Fi routers and phones, before they can be marketed in the US. It was originally a technical check on radio emissions, but it has increasingly been used to block equipment that US authorities consider a national security risk.
Why are routers considered a security risk?
Routers sit between a home or office network and the internet, so all connected devices usually send traffic through them. A router with a serious software flaw, outdated firmware or harmful modifications could expose that traffic or be taken over by attackers. Security researchers have long warned that consumer routers across many brands are often poorly maintained and rarely updated.
Sources and further reading
- Ars Technica: technology policy reporting on Florida’s lawsuit against TP-Link and the FCC ban on its latest routers
- Federal Communications Commission: public materials explaining equipment authorisation and security-related restrictions on communications equipment
- State attorneys general offices: official announcements and court filings for consumer protection lawsuits
- Cybersecurity agencies and independent security researchers: general guidance on securing home routers and firmware
Surfaced from the rss:arstechnica signal “router maker regulatory scrutiny”. AI-assisted draft, editorially reviewed.

