Hello, this is Ryuta Hamamoto from TIMEWELL.
On March 23, 2026, the U.S. Federal Communications Commission issued a press release that moved quickly through security and retail channels. It announced a ban on imports and new certifications of new consumer-grade routers manufactured overseas. FCC Chair Brendan Carr’s statement put the rationale in national-security language: routers produced in foreign countries can pose unacceptable risks to U.S. national security or to the safety and security of the American people12.
The brand most people immediately associate with the measure is TP-Link, which has deep roots in Shenzhen and a very large share of the U.S. home and small-office router market. Texas litigation materials put that U.S. share above 65 percent. TP-Link has contested the figure. Either way, the company is one of the most widely deployed consumer router brands in the United States, and it has been repeatedly linked in public reporting to campaigns that abused vulnerable SOHO gear through 2024 and 202534.
I work in AI and organizational change, not as a network-forensics lab. What pulled me into this story is simpler. A device class treated as commodity infrastructure is now being treated as a trust decision. Japan’s market makes that hard to ignore from my side of the Pacific. BCN Ranking data put TP-Link at 59.9 percent of Japan Wi-Fi router unit sales in 202456. Equipment restricted for new U.S. import is still a default shelf item in many other markets. That gap is the real subject of this piece: how governments, companies, and households should think about supply-chain trust when the product is cheap, popular, and always on.
Why routers became a national-security object: vulnerabilities plus real abuse
The U.S. political track did not start in March 2026. In August 2024, a bipartisan group of members of Congress asked the Department of Commerce to investigate TP-Link products and used a phrase that stuck in coverage: “anomalous level of vulnerabilities.” That is stronger language than ordinary product-defect talk.
Technical findings kept the pressure on. In 2025, a critical authentication-bypass issue tracked under a CVE-2025 reference was disclosed and patched. Reporting described a path that could let an attacker bypass router authentication and write new firmware, a class of flaw that security teams treat as backdoor-adjacent even when no manufacturer intent is proven7. Bugs alone do not make policy. Who exploits them, and at what scale, does.
That is where Volt Typhoon enters the public record. CISA and the FBI have described Volt Typhoon as a state-sponsored actor linked to the People’s Republic of China, with multi-year presence around U.S. critical infrastructure. JPCERT/CC’s write-up emphasizes “living off the land”: abusing legitimate tools and devices already inside a network so malicious activity hides inside normal logs8. Quiet work lasts longer than loud malware.
Vulnerable home and small-office routers became part of that hideout. Public accounts describe large-scale compromise of SOHO routers into botnets such as the KV Botnet, then use of that infrastructure as relay capacity against targets that include electric utilities, water systems, telecom providers, and military-related facilities. Ordinary household gear can become someone else’s operational platform.
The Department of Justice ran a disruption operation against a Volt Typhoon-built botnet in December 2023. Follow-on campaigns have continued. On April 23, 2026, Japan’s National Cybersecurity Office co-signed a UK-led international advisory warning about China-linked covert networks of compromised devices9. Ten countries signed: the United Kingdom, the United States, Australia, Canada, Germany, the Netherlands, New Zealand, Spain, Sweden, and Japan. That list is the policy signal. This is not a one-regulator grievance.
Headquarters moves, manufacturing reality, and competing claims
TP-Link’s public line, including statements on its Japan site, is that TP-Link Systems is headquartered in the United States, in Irvine, California, and is committed to complying with U.S. law after a headquarters relocation around 202310. Founded in Shenzhen in 1996, the company now presents itself as a U.S. corporate citizen for regulatory purposes.
U.S. government actors have not treated the move as the end of the structural question. The February 2026 lawsuit filed by Texas Attorney General Ken Paxton alleges that products labeled as made in Vietnam still depend on China-centered manufacturing and management, and argues Chinese Communist Party influence over that reality34. Those are allegations in litigation, not final court findings. Readers should keep that distinction.
The analytical point does not require settling the lawsuit. Trust questions for network gear turn less on the mailing address of headquarters and more on who develops and signs firmware, who controls manufacturing lines, and who can compel cooperation under domestic intelligence law. China’s National Intelligence Law, enacted in 2017, includes obligations for Chinese companies and individuals to support state intelligence work. U.S. officials treat that structure as a residual risk even after a corporate re-domicile. Similar concerns have shaped earlier policy toward other Chinese network vendors. Rehearsing that history is not the same as proving a specific backdoor in a specific SKU.
Market-share numbers are also contested. Texas materials cite about 65 percent U.S. share. TP-Link has pointed to its own 2024 research putting the figure near 36.6 percent. Both can be directionally useful without either being gospel. What matters for risk is deployment density. A widely installed gateway multiplies the blast radius of any common flaw.
Take AI-driven development all the way to production
WARP is a hands-on program for teams who want more than headlines. Former enterprise DX and data strategy leads work alongside you until it runs.
What the FCC ban covers, and what it carefully does not
Misreadings of the March 2026 announcement spread quickly. Precision helps.
The ban targets imports and new certifications of new consumer-grade routers manufactured overseas. Existing inventory already lawfully in the United States can continue to be sold by retailers under the announced terms. Devices consumers already own do not become illegal to keep using. The FCC has been explicit on continued use.
A parallel mitigation matters for households and small businesses. For overseas-made drones and routers on the ban list, firmware security updates are scheduled to remain available through January 2029. That is a transition bridge, not a claim that the devices are risk-free.
“U.S.-made” is also less simple than the headline. Reporting summarized by Forbes Japan notes that even a U.S.-headquartered firm that designs and develops software domestically can still fall on the wrong side of the rule if component mounting and final assembly are outsourced to Taiwan, Vietnam, China, or other foreign locations11. In practice, many major consumer brands are affected. Fully domestic consumer-router manufacturing is scarce. U.S. shoppers should expect a messy transition period, not an instant shelf of perfect substitutes.
Read that way, the measure is a supply-chain trust reset for a device class, not a neat “country-of-brand” filter.
Why non-U.S. markets still matter, including Japan’s ~60% share
From Japan, the story is not theoretical. BCN Ranking’s 2024 full-year tally put TP-Link at 59.9 percent of Wi-Fi router unit sales5. Walk an electronics retail ranking or an Amazon bestseller list and the brand density is obvious. Prices are competitive. Wi-Fi 6 and Wi-Fi 7 support arrived early. Local-language support is strong. Consumers made rational purchase choices. Those choices also distributed a single vendor’s risk across a large share of home gateways.
A home router is the first hop between the public internet and nearly every device in the building: phones, PCs, TVs, cameras, and other IoT gear. If firmware is compromised, intentionally or through unpatched flaws, traffic that passes the box is exposed to interception and manipulation risk. That is true for any brand. Concentration makes the same flaw more consequential.
Corporate and public-sector procurement adds another layer. Cost-focused buying has put inexpensive consumer or prosumer routers into SME offices, local government sites, hospitals, and schools more often than security teams like to admit. Security practitioners in Japan have said out loud that TP-Link gear shows up in organizational networks more often than inventory systems suggest12. Translating the U.S. Volt Typhoon pattern into another country’s infrastructure is not a claim that the same campaign is already inside every utility. It is a claim that the attack class is portable: compromise edge devices, stay quiet, move toward higher-value networks.
Japan’s current law does not ban private purchase or use of these routers. Government procurement has been building guidelines since 2020 to exclude equipment and software with security concerns, but those rules do not fully cover private-sector and SME buying. That gap is a policy debate Japan still has to finish. Other countries will face their own versions of the same question.
Fair questions: intent, trade policy, and what “dangerous” should mean
Honesty requires a counter-argument that has appeared in security media. Brian Krebs and others have questioned whether vulnerability counts alone justify a brand-specific or class-wide ban, and whether trade conflict is doing some of the work that pure risk analysis cannot finish. That skepticism is healthy. Public evidence of intentional manufacturer spyware is not the same as a long CVE history. Vulnerabilities Volt Typhoon abused may also exist, in different forms, across other SOHO brands.
None of that supports a shrug. Three points still stand.
First, regardless of manufacturer intent, vulnerable devices were used as real attack infrastructure by state-linked actors. That operational fact does not depend on a smoking-gun backdoor narrative.
Second, structural legal risk under a foreign intelligence-cooperation regime is a forward-looking problem. “No intentional implant has been proven today” does not answer “who can compel a firmware change tomorrow.” National-security policy often acts on that class of unprovable future risk. You can disagree with the policy and still describe it accurately.
Third, swapping one brand for another brand with the same supply-chain structure does not solve the problem. Cameras, smart speakers, IoT appliances, and cloud services raise parallel questions. A single-vendor ban is not a digital supply-chain strategy. It is one instrument inside a larger trust model that most organizations have not written down.
What companies and individuals can do this week
Start with inventory if you run a company network. List routers, switches, and access points by site, manufacturer, and model. Flag which of them handle paths to business data, customer data, or intellectual property. Replacement priority should follow data sensitivity and exposure, not only brand reputation.
Firmware discipline is the cheapest control that still works. Apply vendor updates. Many incidents ride known flaws that already had patches. Default passwords and open remote management remain common, across brands. Close them.
Alternative selection is a procurement problem, not a purity test. In Japan, domestic makers such as Buffalo and I-O Data are common consumer and SMB options. Enterprise environments often look to vendors with stronger security track records and support models, including U.S. network and security vendors such as Cisco, Juniper, and Fortinet. Cost, management complexity, and staff skill still matter. A “secure” box that nobody patches is not a secure box.
For households, three habits cover most of the practical ground. Check for firmware updates. Change the default admin password. Disable remote management if you do not need it. Those steps apply whether the router was made in the United States, Japan, Vietnam, or China.
Trust as infrastructure, not as a slogan
Routers are boring on purpose. You plug them in and forget them for years. That forgetfulness is why they are attractive as long-term footholds. The U.S. measure is easier to understand as a precautionary judgment about trustworthiness of a supply chain than as a completed technical proof about one vendor’s source code. Waiting for perfect proof before acting is one policy choice. Acting on structural risk is another. Both have costs.
Japan and many other markets still optimize consumer networking for price and features first. A 60 percent shelf share is the result of that optimization. Adding “is the supply chain trustworthy enough for this network’s role?” to the buying criteria does not require panic. It requires a written standard. Looking up the model number on the box in your closet takes a few minutes. That is a reasonable place to start.
Folding supply-chain security into company strategy
If the open question is “where does our company even start,” you are not alone. Edge hardware, firmware update authority, and outbound data paths are now board-adjacent topics, not only IT ticket topics.
TIMEWELL’s WARP consulting helps teams inventory AI and IT supply-chain risk while designing AI deployment strategy. Which vendors own which devices and software. Who controls firmware and model updates. Which paths can carry business information out of the company. Those questions need both operator language and executive language.
Companies that build generative AI and internal systems also face a parallel issue: how much internal knowledge already sits in external SaaS. Interest in enterprise AI that can run on Japan-based infrastructure, such as ZEROCK, sits on the same trust line as router supply-chain questions, even though the technical stack is different.
If you want help turning device inventory and software inventory into a decision pack leadership can use, reach out.
References
Footnotes
-
ASCII.jp. U.S. moves against foreign-made routers, citing “anomalous level of vulnerabilities” around China-based TP-Link. https://ascii.jp/limit/group/ida/elem/000/004/400/4400790/ (2026) ↩
-
Reuters. U.S. authorities ban imports of new foreign-made routers over security concerns. https://jp.reuters.com/business/technology/ZJRRPTR2VVKHPLDKBEKX4AVNV4-2026-03-24/ (2026-03-24) ↩
-
GIGAZINE. Texas sues TP-Link over alleged aid to cyberattacks linked to the Chinese Communist Party. https://gigazine.net/news/20260219-tp-link-hacking/ (2026-02-19) ↩ ↩2
-
Codebook. Texas files suit against TP-Link over China ties and vulnerability issues. https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/43958/ (2026-02-18) ↩ ↩2
-
BCN Retail. TP-Link surges in wireless LAN router popularity rankings. https://www.bcnretail.com/research/detail/20260413_618449.html (2026-04-13) ↩ ↩2
-
xexeq.jp. TP-Link Wi-Fi 7 router coverage noting 59.9% Japan share. https://xexeq.jp/blogs/media/topics37578 (2024) ↩
-
Codebook. TP-Link patches critical authentication bypass vulnerability (CVE-2025). https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/44805/ (2025) ↩
-
JPCERT/CC. How to prepare for the Volt Typhoon attack campaign. https://blogs.jpcert.or.jp/ja/2024/06/volt-typhoon-threat-hunting.html (2024-06) ↩
-
National Center of Incident Readiness and Strategy for Cybersecurity (NISC). Joint signing of the advisory on defending against China-linked covert networks of compromised devices. https://www.cyber.go.jp/pdf/press/Defending_against_China_linked_covert_networks_of_compromised_devices.pdf (2026-04-23) ↩
-
TP-Link Japan. Statement from U.S. headquarters regarding recent media reports. https://www.tp-link.com/jp/press/news/21538/ (2025) ↩
-
Forbes JAPAN. U.S. fully bans sales of foreign-made routers — what can consumers buy? https://forbesjapan.com/articles/detail/94909 (2026) ↩
-
Security Measures Lab. U.S. bans new sales of overseas-manufactured routers for security reasons — impact on TP-Link and Japan. https://rocket-boys.co.jp/security-measures-lab/sada-hospital-nurse-sns-post-medical-record-image-leak-privacy-risk-2/ ↩





