Five attorneys general just turned your closet full of cheap routers into a live procurement case.
Florida, Iowa, Montana, and Nebraska sued TP-Link Systems on October 6, joining Texas, which filed in February. The states say the California company misled buyers about how secure those boxes are and how separate the firm really is from China. TP-Link denies the claims and says it will fight them in court. You still have to decide whether those devices stay in the path of your cybersecurity program while lawyers argue about brochures.

Cybersecurity Brochures Do Not Patch Firmware
The complaint is a consumer-protection case. Your problem shows up in firmware, WAN management toggles, and who can hit the admin port from the parking lot.
Plenty of branch offices still hang a consumer or SMB router off a cheap ISP handoff and treat it as the office firewall. Remote management gets flipped on for a vendor visit and never flipped off. Default accounts linger because the person who unboxed it left last year.
That admin page is a brute-force surface with a pretty logo.
Your threat detection probably never sees it.
I keep watching shops buy the inexpensive box, trust the packaging, and assume some upstream threat-protection product will cover the rest. Defense in depth requires a second control you actually operate. A power cord and a story do not qualify.
A courtroom denial does not rotate a factory password.
The same week, researchers at Lava found hundreds of internet-exposed GPU servers running NVIDIA’s DCGM Exporter with CVE-2026-47483 sitting open. Unauthenticated attackers can crash the monitoring service and may disrupt AI workloads. NVIDIA rated it 8.2 and published a bulletin on July 28. Different vendor. Same pattern. You put a management plane on the network and believed it would only speak to you.
You already know how this plays out in tickets. Someone enables UPnP to make a camera work. Someone forwards 443 to the router UI so they can “just check it from home.” Months later the change record is gone and the box is still doing both. Security hardening that never includes the device you forgot to name will fail on schedule.
For cyber security operators, the lesson is blunt. Routers, exporters, and cloud-managed “smart” gateways are privileged identity. Treat the brochure as advertising.
Harden Every Management Plane You Inherited
You don’t need a new platform. You need an inventory and a change window.

Do this now, then keep doing it.
- Inventory every edge router, Wi-Fi gateway, and GPU or lab exporter by serial, firmware, and which networks can reach the admin or scrape port.
- Disable WAN-side remote management. Put remaining admin interfaces behind a jump path your firewall actually filters.
- Replace factory passwords, kill unused local accounts, and ship whatever logs the device has into the same place you watch for brute-force.
- Patch DCGM Exporter, then pull scrape endpoints off the public internet. If you can’t patch this week, block unauthenticated access at the host firewall.
- Ban source IPs that hammer admin, SSH, or scrape ports after a short threshold. IP bans are dull. They still cut noise while security hardening catches up.
- Put consumer-grade gear on a replacement calendar that demands signed updates and a public defect process.
- Rehearse incident response as if the router is hostile: snapshot the config, isolate the WAN, rotate every credential that traversed that box, and check for unexpected DNS or VPN peers.
None of this is glamorous. It’s the work that still matters when a vendor’s independence story is a courtroom exhibit.
Courts Will Not Run Your Incident Response
Florida can file. Iowa can file. You still own the blast radius if someone walks the default UI or crashes the GPU monitor during a training job.
Verdicts take years. Firmware lasts as long as the device stays powered. If a box cannot show signed updates, an admin plane you can isolate, and logs you can query, it does not belong on a trust boundary.
Procurement teams love unit price. Attackers love the same SKU in every closet with the same default HTTPS port. Price is not a control.
Ask vendors for the signing key story, the CVE mail list, and whether remote cloud management can be fully disabled. If they stall, you have your answer. Put that in the purchase file next to the quote.
If legal is going to argue about China ties for years, your control is simpler. Assume update servers, cloud-mgmt callbacks, and crash-only exporters can fail or lie. Build the network so that failure is loud and local.
Keep a spare known-good image for whatever you still run. Segment guest and IoT SSIDs so a cheap AP cannot see finance VLANs. When the next complaint lands, you should already know every serial number, every WAN management flag, and every scrape endpoint.
Replace the fleet on your calendar, not the docket.
Sources
- TP-Link Sued by Four More U.S. States Over Router Security and China Ties
- High-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
