US lawmakers push for investigation amid cyberattack concerns about TP-Link

August 17, 2024
1 min read


TLDR:

US lawmakers are urging a probe into TP-Link due to fears of possible cyberattacks, citing vulnerabilities in TP-Link devices used for malicious purposes. The investigation is in response to concerns about national security risks posed by China-affiliated routers.

Summary:

Two representatives of the House Select Committee on China have called for an investigation into TP-Link over possible national security risks. This comes after previous incidents of TP-Link device vulnerabilities being exploited for espionage. The known vulnerabilities in TP-Link devices are seen as a glaring national security issue, prompting the lawmakers to reach out to Commerce Secretary Gina Raimondo.

The US Cybersecurity and Infrastructure Agency (CISA) highlighted potential vulnerabilities in TP-Link routers that could be exploited for remote code execution. Additionally, a US security company found evidence of a Chinese state-sponsored cyber group spying on European officials by implanting malware in TP-Link routers.

While TP-Link denies any security vulnerabilities in its products and mentions that their routers are not sold in the US, concerns about China targeting Wi-Fi routers for cyberattacks persist. The Chinese Embassy has called for evidence-based identification of cyber-related incidents rather than speculative allegations.

The US and allies have released intelligence suggesting that China may exploit Wi-Fi routers for clandestine attacks on critical infrastructure. However, it was clarified that the routers cited in the intelligence were manufactured by Cisco and Netgear, not TP-Link.

Overall, the call for a probe into TP-Link underscores growing concerns about cybersecurity threats posed by foreign entities and the need to protect network infrastructure from potential cyberattacks.


Latest from Blog

EU push for unified incident report rules

TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and