Chinese and Russian intelligence agencies can walk right through the Wi-Fi routers sitting in millions of American homes — and the federal government blocked new imports but left the old devices right where they are.

Republican attorneys general in Nebraska, Florida, Iowa and Montana sued TP-Link Systems Inc. on Tuesday, accusing the router giant of lying about its China ties and selling devices with security flaws that foreign militaries are already exploiting. TP-Link controls at least 60% of home and small-office routers sold in U.S. stores, according to former NSA cybersecurity director Rob Joyce's March 2025 testimony before Congress. That is an enormous installed base of potentially compromised hardware sitting in American living rooms.

The Federal Communications Commission blocked new foreign-made routers in March, but its order does nothing about devices already in use. The Department of Defense designated TP-Link Technologies a Chinese military company in June. The company has roughly 11,000 workers in China and only about 305 in the U.S., Bloomberg reported.

TP-Link told customers its ties to China "have been severed," Nebraska Attorney General Mike Hilgers said in a statement. "In truth, TP-Link's products and systems still have strong connections to China, and its supply chain continues to be intertwined with China's state-sponsored technology ecosystem."

Russia's military intelligence agency already found an exploit in TP-Link's TL-WR940N router to spy on users' web traffic, the FBI warned in April. The company sold that model through 2024. Two versions of the Archer C7, which TP-Link advertised as providing "secure Wi-Fi access for guests sharing your home or office network," were hijacked by a network known as Quad7, the lawsuits allege.

"Some of these older routers can be easily exploited by other foreign intelligence agencies," Hilgers told the Daily Caller News Foundation. He urged Americans to check whether their router is still receiving firmware updates, install available patches, and replace default passwords.

TP-Link corporate affairs officer Steve Kovsky called the lawsuits "built on false premises" in a Tuesday press release. "They do nothing to advance national security while unfairly penalizing an industry-leading U.S. company," Kovsky said. The California-based company said it spent months giving state regulators records showing its U.S. routers are made in Vietnam and no foreign government owns or controls it.

The failure isn't limited to home networks. Business Insider reported this week that SpaceX warned Chinese satellite operators are refusing to share trajectory data, creating dangerous collision risks with the Starlink network. The vast majority of satellites that had close encounters with Starlink this year without sharing their position originated in China, SpaceX said — including one near-miss that came within 57 meters. Whether it's routers in your house or satellites over your head, Chinese state-linked entities are operating inside critical American infrastructure without following the rules, and the government response is the same: announce a measure that sounds tough, leave the threat in place, and ask for more authority over citizens.

Hilgers said the state would welcome TP-Link pulling the routers from shelves, but at a minimum wants the company to warn buyers. "If you have these kinds of products that have known security loopholes and flaws that allow hackers and others to be able to reach the sensitive information of Nebraskans, then you should tell people that," he said.

The FCC blocked new TP-Link imports. The Pentagon labeled the parent company a Chinese military entity. Neither agency pulled the products already in American homes. When both parties agree the threat is real and neither acts, who exactly is being protected?