Nebraska Attorney General Mike Hilgers today led a multi-state coalition of 21 state attorneys general in raising concerns over TP-Link routers in a letter addressed to the Federal Communications Commission regarding TP-Link’s request for conditional approval to sell new router models in the United States. The letter follows a lawsuit filed on Tuesday to address state law violations related to TP-Link’s deceptive statements to consumers regarding its routers’ privacy and security.
TP-Link controls at least 60 percent of the U.S. retail market for Wi-Fi systems and small office/home-office routers. As the FCC’s March 23, 2026, Public Notice explained: “Routers are the key networking device that enable American homes, schools, businesses, critical infrastructure providers, and emergency services to connect to the internet every day. … Compromised routers can enable in-depth network surveillance, data exfiltration, botnet attacks, and unauthorized access to U.S. Government or American businesses’ networks.”
The letter addresses concerns that TP-Link has ongoing ties to the Chinese military and relies on major research and development and manufacturing operations in China. Although TP-Link recently constructed a manufacturing plant in Vietnam, a vast majority of the components used at the plant are imported from or through China, and the plant was constructed by a contractor with ties to the Chinese military. These ongoing relationships create serious security concerns that must be addressed before a decision is made on TP-Link’s request for conditional approval.
“TP-Link’s products and systems still have strong connections to China, and its supply chain continues to be intertwined with China’s state-sponsored technology ecosystem,” Attorney General Hilgers said. “Consumers should be aware of these risks and the FCC should address them before authorizing these new routers for sale in U.S. markets.”
TP-Link routers have been implicated in a number of serious cyber-attacks by Russian intelligence and Chinese state actors. The attacks involved unauthorized access to TP-Link routers, which enabled hackers to gain administrator access and conscript the routers into an illegal botnet. Hackers can use botnets to gain access to targeted systems, or to steal consumers’ sensitive information, including private communications, usage data, passwords, financial records, and more.
Joining Attorney General Hilgers in sending the letter are attorneys general from the following states: Alabama, Alaska, Arkansas, Georgia, Idaho, Indiana, Iowa, Kansas, Kentucky, Louisiana, Montana, North Dakota, Ohio, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, and West Virginia.
