TRAFEED

FCC Foreign-Made Router Controls and Smart TV Data Cases: What the Record Shows on Chinese-Linked Devices

Published2026-02-23Updated2026-08-09Ryuta Hamamoto

U.S. actions on Chinese-made networking gear and related device risk. FCC Covered List moves, litigation context, and what buyers should document in procurement.

FCC Foreign-Made Router Controls and Smart TV Data Cases: What the Record Shows on Chinese-Linked Devices
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

The Wi-Fi router in a US living room and the smart TV next to it are ordinary products. They are also network edge devices that process traffic and, in many designs, viewing data. Over the past year, federal technical regulation, state consumer litigation, and public cyber reporting have all tightened the spotlight on where devices are designed, built, and controlled — and on what data they send off-premises.

I first published this article in February 2026, when Texas state suits were the main public story and a reported Commerce Department track aimed at TP-Link products had been set aside ahead of high-level US–China meetings. Six months later, the federal picture is different. In March 2026, the FCC updated its Covered List to include certain foreign-made consumer Wi-Fi routers, with authorization consequences for new models. The FCC's reading of "produced" looks past final assembly labels toward design and development location. That is a technical-regulatory move, not a criminal verdict against any brand.

This rewrite sticks to public primary and secondary sources, separates allegations from findings, and treats list placement and lawsuits as regulatory and procedural facts — not as moral judgments about the companies named in those records. If you want a quick read on your own export-control and counterparty process, start with our free export-control readiness check.

Issue February 2026 (first version) August 2026 (now)
Federal track Reported Commerce action on TP-Link products set aside FCC adds foreign-made consumer routers to Covered List
State track Texas DTPA suits filed Suits and related orders continue; multi-state follow-on remains a watch item
EAR Affiliates Rule (50%) Expected return path into late 2026 Effective once, suspended one year, scheduled return November 10, 2026
Typhoon-linked reporting Telecom intrusion and long-dwell access Broader geographic reporting; OT-oriented tradecraft discussed in industry research

Texas filed five China-linked consumer cases in one week

On Monday, February 17, 2026, Texas Attorney General Ken Paxton announced a suit against TP-Link related to Wi-Fi routers.[1] Subsequent filings the same week named drone seller Anzu Robotics, baby-monitor company Lorex, and e-commerce platforms Temu and Shein.[2] The industries differ. What the AG's office emphasized was alleged ties to the People's Republic of China and data or origin concerns under Texas consumer law.

Paxton's office framed the week as a coordinated series of actions. The legal form is primarily consumer protection under Texas statutes such as the Deceptive Trade Practices Act. National-security vocabulary appears in public statements and complaints; that rhetoric is advocacy, not a federal designation by itself.

Public materials also show longer preparation: investigation activity described from late 2025, and Texas measures affecting state employee use of certain TP-Link products.[1] Treat the suits as pending or ongoing litigation unless a final judgment says otherwise.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

Among the five matters, the TP-Link complaint drew the most attention for its language. Court filings and AG releases describe routers as critical home-network gateways and raise two themes that compliance teams should track as risk signals, not as adjudicated facts:

  1. Origin and operations — allegations that products labeled with one country of final assembly remain substantially designed, supplied, or operated through China-linked structures.[2]
  2. Security history — references to public reporting that compromised SOHO routers, including TP-Link models in some campaigns, were used as infrastructure in password-spray and related activity.

On the second theme, Microsoft described Chinese state-linked activity (Storm-0940) using credentials from password spray via a covert network that included compromised routers (Quad7 / related reporting).[4] CISA's Known Exploited Vulnerabilities Catalog has listed multiple TP-Link product CVEs that were observed as exploited in the wild.[5] Those are vulnerability and threat-intel facts. They do not, standing alone, prove company intent or a court finding of liability in the Texas case.

China's National Intelligence Law (2017), Article 7, requires organizations and citizens to support, assist, and cooperate with state intelligence work in accordance with law.[3] Western risk assessments often cite that statute when evaluating PRC-incorporated vendors. Citation of the statute is a legal-environment fact. It is not a finding that any particular company has turned over customer data.

TP-Link has publicly stated that its relevant US-facing entity is headquartered in Singapore and is not under PRC government control.[6] Texas materials emphasize supply-chain and operational substance over legal domicile. Covered List treatment, AG filings, and company rebuttals can all be true as records without any of them being a final judicial determination of wrongdoing.

Smart TV ACR cases: viewing data, not export licenses

In December 2025, Texas sued five TV makers — Sony, Samsung, LG, Hisense, and TCL — over Automatic Content Recognition (ACR) and related viewing-data practices.[7] ACR systems identify content on-screen and collect viewing data. Complaints and privacy reporting describe default-on settings and collection that can extend beyond linear TV to other on-screen sources depending on implementation.[10]

The AG's office obtained temporary court relief limiting certain ACR collection by Hisense in Texas[8] and announced related relief involving Samsung.[9] Those orders are procedural outcomes in consumer privacy litigation. They are not export-control classifications, and they do not establish that every named manufacturer violated a final judgment on the merits. Ownership structures among the five defendants also differ materially; do not collapse them into a single "Chinese TV" category.

Practical takeaway for households and corporate facilities: review ACR and related privacy settings on smart displays. Default-on telemetry is a product design choice that privacy teams should inventory.

On drones and baby monitors, Texas filings allege rebranding and component-origin issues involving parties that appear on various US government lists.[2] Department of Defense "Chinese military company" style listings are regulatory classifications. They are not criminal convictions. Keep that distinction when briefings travel from legal to board level.

Party (as named in public Texas materials) Product area Nature of public claim (allegations unless noted)
TP-Link Wi-Fi routers Origin / China-link disclosures; security history referenced via third-party reporting
Hisense, TCL Smart TVs ACR data collection; National Intelligence Law cited as environment risk in advocacy
Sony, Samsung, LG Smart TVs ACR / privacy practices (ownership structures differ from PRC-headquartered peers)
Anzu Robotics Drones Alleged rebrand relationship to DJI products (unproven in a final merits judgment here)
Lorex Baby monitors Alleged use of components tied to listed organizations
Temu, Shein E-commerce apps Alleged aggressive data collection practices

Salt Typhoon and Volt Typhoon: why edge devices stay on the threat brief

State litigation did not arise in a vacuum. Public US reporting describes long-running cyber operations attributed by the US government and industry to PRC state-sponsored actors.

Salt Typhoon reporting from 2024 onward describes deep access into major US telecommunications providers, including systems associated with lawful intercept processes, and large-scale metadata exposure concentrated around the Washington, D.C. region.[11][12] Later reporting and FBI statements described activity spanning many countries and hundreds of organizations.[13] Separate 2025–2026 reporting discussed further targeting of government-adjacent communications. Treat evolving news as reporting, and use CISA/FBI primary advisories where available for defensive priorities.

Volt Typhoon is described in CISA joint advisories as pre-positioning in critical infrastructure networks — power, water, telecom — with living-off-the-land techniques that abuse legitimate admin tools.[14] The FBI has announced botnet disruption actions against related infrastructure.[15] Industry research in 2025–2026 has discussed movement toward OT-connected environments and long-dwell access that defenders may never fully eradicate.[16]

Cluster (public naming) Assessed objective (USG/industry) Primary environments discussed Methods highlighted
Salt Typhoon Intelligence collection Telecom, high-value communications Abuse of privileged network functions; large-scale metadata access
Volt Typhoon Pre-positioning for disruption in crisis Critical infrastructure IT and, increasingly, OT-adjacent systems Living off the land; long dwell; botnet support infrastructure

SOHO routers and other always-on edge devices matter in this picture because compromised consumer gear has been documented as relay infrastructure in other campaigns. That is a systems-security reason to care about patching, vendor selection, and network segmentation — separate from any single lawsuit.

Federal action that landed: FCC Covered List and foreign-made routers

Two federal tracks are easy to confuse:

  1. Commerce / export-trade measures aimed at particular vendors (including reported TP-Link-focused options that were set aside in early 2026 reporting).[17]
  2. FCC Covered List measures under the Secure and Trusted Communications Networks Act framework — the track that did produce a March 2026 update for foreign-made consumer routers.[18]

Under the Covered List update, new models without required FCC equipment authorization face effective barriers to US import and sale. Devices already in use generally continue to operate. Authorized models can remain available.[19][21] Public coverage noted conditional authorization pathways for some vendors (for example Netgear and Eero through a stated horizon) and that TP-Link did not obtain the same conditional treatment in the materials those outlets described; TP-Link has publicly discussed expanding manufacturing footprint including US capacity.[20] Market-share figures for TP-Link in US retail Wi-Fi vary by source and date; treat any single percentage as estimate, not regulation.[22][6]

Most important for supply-chain teams is the FCC's broad reading of "produced": not only final assembly location, but design and development activity abroad can bring a product into foreign-produced treatment.[19] Labeling "Made in Vietnam" after PRC-centric design and component sourcing may not settle the regulatory question. That is the same substance-over-label instinct state complaints raised — now expressed through federal equipment authorization rules.

What US companies should do with this stack of facts

If you operate networks, sell into regulated sectors, or export items subject to the EAR, the action list is operational:

  1. Inventory edge devices (routers, cameras, smart displays, industrial IoT gateways) by model, firmware, vendor, and authorization status.
  2. Separate privacy risk from export risk. ACR settings are a privacy/compliance workstream. Covered List and EAR screening are trade and telecom-security workstreams.
  3. Verify origin and ownership, not only packing-slip country. Design location, ultimate parent, and listed-party equity stakes all matter under different regimes.
  4. Patch and segment. KEV-listed vulnerabilities on SOHO gear are a concrete hygiene task regardless of brand politics.
  5. Prepare for the BIS Affiliates Rule return on November 10, 2026. Ownership of 50% or more by certain listed parties can import license requirements onto unlisted affiliates. Full calculation patterns and Red Flag 29: BIS 50% Rule complete guide. Primary stay text: Federal Register FR Doc 2025-19846.[23]

TRAFEED supports the screening and ownership-mapping side of this problem: multi-list restricted-party checks, capital-relationship context, and classification decision support for dual-use shipments. Final license and procurement decisions stay with your compliance owner. For program design, book a consultation or review the TRAFEED catalog (PDF).

Internal knowledge control is a parallel track when the concern is data exfiltration rather than outbound dual-use licensing. ZEROCK focuses on GraphRAG-based knowledge management so organizations can see who can reach which sensitive materials — useful when supply-chain briefings and design files should not sprawl across unmanaged shares.

The through-line is not "ban every Chinese-branded product tomorrow." It is that US regulators and state AGs are acting on origin, ownership, data practices, and cyber history with more force than packing labels can absorb. Programs that still equate "not on a sanctions list" with "cleared" will under-read Covered List authorization, privacy litigation, and 50% ownership rules that never print the affiliate's name.


References

[1] Texas Attorney General. (2026, February 17). Attorney General Paxton Sues TP Link for Allowing the CCP to Access Americans' Devices. https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-sues-tp-link-allowing-ccp-access-americans-devices-first-several-lawsuits

[2] Texas Policy Research. (2026, February 20). Texas Files Four Major Lawsuits Against CCP-Linked Companies. https://www.texaspolicyresearch.com/texas-files-four-major-lawsuits-against-ccp-linked-companies/

[3] China Law Translate. (2017). PRC National Intelligence Law. https://www.chinalawtranslate.com/en/national-intelligence-law-of-the-p-r-c-2017/

[4] Microsoft Security. (2024, October 31). Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network. https://www.microsoft.com/en-us/security/blog/2024/10/31/chinese-threat-actor-storm-0940-uses-credentials-from-password-spray-attacks-from-a-covert-network/

[5] CISA. Known Exploited Vulnerabilities Catalog. https://www.cisa.gov/known-exploited-vulnerabilities-catalog

[6] TP-Link. (2025, March 5). TP-Link Systems Inc. Sets the Record Straight Regarding Inaccurate U.S. Market Share Data. https://www.tp-link.com/us/press/news/21656/

[7] Texas Attorney General. (2025, December 15). Attorney General Paxton Sues Five Major TV Companies, Including Some with Ties to the CCP, for Spying on Texans. https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-sues-five-major-tv-companies-including-some-ties-ccp-spying-texans

[8] Texas Attorney General. (2025, December 17). Attorney General Ken Paxton Secures Court Order Stopping CCP-Aligned Smart TV Company from Spying on Texans. https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-court-order-stopping-ccp-aligned-smart-tv-company-spying-texans

[9] Texas Attorney General. (2026, January 6). Attorney General Ken Paxton Secures Major Win, Stopping Samsung from Using Its Smart TVs to Illegally Spy. https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-major-win-stopping-samsung-using-its-smart-tvs-illegally-spy

[10] IAPP. (2026, January 26). Automated content recognition technology takes privacy enforcement spotlight. https://iapp.org/news/a/automated-content-recognition-technology-takes-privacy-enforcement-spotlight

[11] Congress.gov (Congressional Research Service). Salt Typhoon Hacks of Telecommunications Companies and Federal Response Implications (IF12798). https://www.congress.gov/crs-product/IF12798

[12] The Wall Street Journal. (2024, October 5). U.S. Wiretap Systems Targeted in China-Linked Hack. https://www.wsj.com/tech/cybersecurity/u-s-wiretap-systems-targeted-in-china-linked-hack-327fc63b

[13] Nextgov. (2025, August 27). Salt Typhoon hackers targeted over 80 countries, FBI says. https://www.nextgov.com/cybersecurity/2025/08/salt-typhoon-hackers-targeted-over-80-countries-fbi-says/407719/

[14] CISA. (2023, May 24). PRC State-Sponsored Actor, Volt Typhoon, Compromises U.S. Critical Infrastructure (AA23-144a). https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a

[15] FBI. (2024, September 18). FBI Director Announces Chinese Botnet Disruption at Aspen Cyber Summit. https://www.fbi.gov/news/stories/fbi-director-announces-chinese-botnet-disruption-exposes-flax-typhoon-hacker-group-s-true-identity-at-aspen-cyber-summit

[16] The Record. (2026, February 19). Researchers warn Volt Typhoon still embedded in US utilities. https://therecord.media/researchers-warn-volt-typhoon-still-active-critical-infrastructure

[17] 9to5Mac. (2026, February 18). Federal ban on TP-Link routers shelved, but Texas fights on. https://9to5mac.com/2026/02/18/federal-ban-on-tp-link-routers-shelved-but-texas-fights-on/

[18] FCC. (2026, March). FCC Updates Covered List to Include Foreign-Made Consumer Routers. https://www.fcc.gov/document/fcc-updates-covered-list-include-foreign-made-consumer-routers

[19] FCC. (2026). FAQs on Recent Updates to FCC Covered List Regarding Routers Produced in Foreign Countries. https://www.fcc.gov/faqs-recent-updates-fcc-covered-list-regarding-routers-produced-foreign-countries

[20] Foundation for Defense of Democracies. (2026, June 30). FCC Introduces New Bans on Chinese-Produced Equipment Linked to Cyber Risks. https://www.fdd.org/analysis/2026/06/30/fcc-introduces-new-bans-on-chinese-produced-equipment-linked-to-cyber-risks/

[21] Consumer Reports. What the FCC Ban on Foreign-Made Routers Means for U.S. Consumers. https://www.consumerreports.org/electronics-computers/wireless-routers/foreign-made-routers-fcc-ban-a1057564057/

[22] The Wall Street Journal. (2024, December 18). U.S. Weighs Ban on Chinese-Made TP-Link Router in Homes. https://www.wsj.com/politics/national-security/us-ban-china-router-tp-link-systems-7d7507e6

[23] Federal Register. (2025, November 12). One Year Suspension of Expansion of End-User Controls for Affiliates of Certain Listed Entities (2025-19846). https://www.federalregister.gov/documents/2025/11/12/2025-19846/one-year-suspension-of-expansion-of-end-user-controls-for-affiliates-of-certain-listed-entities

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Economic Security Management Guidelines (1st Edition): 44-Item Self-Check Worksheet (2026)

A fill-in worksheet built from the appendix checklist of the Economic Security Management Guidelines (1st Edition), published by METI's Trade and Economic Security Bureau on 23 January 2026. All 44 items are transcribed from the original text and laid out in its three-column form: check item, Y/N, and the structures (organisation, internal rules) and track record behind your answer. The breakdown follows the original: 5 items on principles executives should keep in mind, 13 on securing autonomy, 13 on securing indispensability, and 13 on strengthening governance, with the 8 items the original phrases as "it is also useful to" badged separately. Opens with a plain-language primer on what economic security, autonomy, indispensability, governance and duty of care actually mean. Includes METI-published survey data showing that 70.7% of 3,007 manufacturers had heard the term but had no concrete image of it, and that the share expecting lost revenue to outweigh the cost of action rises from 22.3% over one to three years to 31.9% over four to ten. As METI states explicitly, the guidelines are not an obligation imposed on companies and are not premised on transactions with any specific country, company, or person. This worksheet was produced by TIMEWELL and was not prepared or endorsed by METI. Final decisions should rest with your legal and compliance leadership and the latest publications of the relevant authorities.

Event Organiser's Migration & Data-Rescue Checklist (fill-in, 2026)

A fill-in worksheet for event organisers whose ticketing service has shut down. PassMarket closed on June 30, 2026, and its ticket management tool is announced as available until August 31, 2026 (planned). The sheet covers what to rescue before that deadline (attendee records, survey responses, revenue and payout records, event page copy, ticket configuration), an inventory of the channels through which you can still reach attendees, a formula and worksheet for calculating the effective cost of a new platform yourself, and the steps to launch a first event on it. Anything the official announcement does not state — when in-service messaging stops, the export specification for attendee lists and survey data, the timing of payouts — is marked "to be confirmed" rather than asserted. It does not rank providers; it supplies the formula and the checklist.

China-Related Transactions Export-Control Screening Sheet (fill-in / Export Control Law & Dual-Use Regulations, critical minerals, Control List, 2026)

A fill-in working sheet for companies trading with China: screen a single transaction against China's export-control regime (the Export Control Law and the Dual-Use Items Export Control Regulations), the controls on critical minerals (gallium/germanium/graphite/antimony/tungsten etc./rare earths/helium), and the four counterparty-list systems (Control List, Watch List, Unreliable Entity List, countermeasure lists). A procedure for "what to check before the deal," not a roster of "who is listed." With a plain-language intro, based on MOFCOM announcements. Listing is a regulatory category, not a judgment about any company (including the Japanese firms on the Japan-directed lists); controls change continually, so verify current announcements and consult your officer. Match counterparties using the original simplified-Chinese wording.

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles