Security vulnerabilities in your home router have been the story for years, with the responsibility being placed at the feet of users to keep their router firmware updated. But a damning report by Fraunhofer says that router manufacturers themselves have taken years to issue patches, with potentially dozens of critical vulnerabilities lurking within older routers.
The June report by Fraunhofer-Institut fur Kommunikation (FKIE) extracted firmware images from routers made by Asus, AVM, D-Link, Linksys, Netgear, TP-Link, and Zyxel127 in all. The report (as noted by ZDNet) compared the firmware images to known vulnerabilities and exploit mitigation techniques, so that even if a vulnerability was exposed, the design of the router could mitigate it.
No matter how you slice it, Fraunhofers study pointed out basic lapses in security across several aspects. At the most basic level, 46 routers didnt receive any updatesat all in the last year. Many used outdated Linux kernels with their own, known vulnerabilities. Fifty routers used hard-coded credentials, where a known username and password was encoded into the router as a default credential that asked the user to change itbut would still be there, accessible, if they did not.
FKIE could not find a single router without flaws. Nor could the institute name a single router vendor that avoided the security issues.
AVM does [a] better job than the other vendors regarding most aspects, the report concluded. Asus and Netgear do a better job in some aspects than D-Link, Linksys, TP-Link, and Zyxel. We contactedBelkin (Linksys) and D-Link, two vendors named in the report, for comment, but didnt hear back by press time.
In conclusion the update policy of router vendors is far behind the standards as we know it from desktop or server operating systems, FKIE said elsewhere in the report. However, routers are exposed to the internet 24 hours a day leading to an even higher risk of malware infection.
Fraunhofer broke down how router vendors have fallen short into several categories.
Days since the last firmware release:Although 81 routers were updated in the last 365 days before the FKIE gathered its results (March 27, 2019 to Match 27, 2020) the average number of days to the prior update, across all devices, was 378. FKIE said 27 of the devices had not been updated within two years, with the absolute worst stretching to 1,969 daysmore then five years.
Asus, AVM, and Netgear issued updates for all of their devices within a year and a half, at least. By comparison, most antivirus programs issue updates at least daily.
Age of the OS: Most routers run Linux, an open-source software model that offers researchers the ability to examine the basic Linux kernel code and apply patches. When the kernel itself is outdated, however, fundamental known vulnerabilities in the OS are ripe for exploitation. FKIE used the open-source Firmware Analysis and Comparison Tool (FACT) to extract the router firmware, finding that a third of the routers ran on top of the 2.6.36 Linux kernel, an older version. Thelast security update for kernel version 2.6.36 was provided nine years ago, the study found.
Critical vulnerabilities in the tested routers abounded. Theaverage number of critical vulnerabilities found for each router was 53, with even the best routers subject to 21 critical vulnerabilities (there were a whopping 348 high-rated vulnerabilities, too).
Exploit mitigation: Routers can be built to protect their kernel using a variety of exploit mitigation techniques, including the non-executable bit (NX) to mark a region of memory as non-executable. This was a common way of protecting the router, but FKIE found that the usage of exploit mitigation techniques was rare.
Private keys: We want to make it absolutely clear that there is no good reason to publish a private key, because a published private key does not provide any security at all! FKIE wrote. Publishing the private cryptographic key in the firmware allows an attacker to impersonate the device itself and do man in the middle attacks, an exploit that tries to fool the users PC and the server into believing that the attacker is the trusted router.
FKIE found that at least five private keys are published per firmware image. The Netgear R6800 provides a total number of 13 private keys in a single device. AVM was the only vendor FKIE found that did not publish private keys.
Hard-coded login credentials: You may already be familiar with hard-coded credentials: a router that uses admin and password as its default credentials. While that makes it easy to recover a lost password, it also makes it extremely easy for an attacker to take over your router. Furthermore, if the user cannot change a password, you might get a feeling that the password is related to a backdoor, FKIE wrote, implying that hard-coding credentials could have been added to allow monitoring of your device.
The good news is that more than 60% of the router firmware images do not have hard-coded login credentials, FKIE wrote. The bad news is that 50 routers do provide hard-coded credentials. Sixteen routers have well known or easy crackable credentials.
FKIEs report doesnt suggest choosing an open-source firmware replacement for your router, although that option is certainly available. Unfortunately, some of the firmware options are no longer maintained, or only work on a subset of (older) routers. Its disappointing that the easiest route for criminals to penetrate your home network appears to benot your PC, or your operating systembut the router youre using to connect to the rest of the world.
This story, "Revealed: How home router manufacturers dropped the ball on security" was originally published by PCWorld.
Go here to read the rest:
Revealed: How home router manufacturers dropped the ball on security - TechHive
- My favourite home security setup is now at its lowest price ever on Amazon - TechRadar - June 12th, 2025 [June 12th, 2025]
- I like this camera-based home security system for its simplicity - PCWorld - June 12th, 2025 [June 12th, 2025]
- I replaced my Ring with this subscription-less security camera - and it did some things better - ZDNET - June 12th, 2025 [June 12th, 2025]
- I found terrifying smart home security holes and you probably have them too - Android Police - June 12th, 2025 [June 12th, 2025]
- You Might Be Being Watched Through Your Home Security Camera. Heres What To Know. - MSN - June 12th, 2025 [June 12th, 2025]
- Wyoming Starter Homes are Affordable on a $75k SalaryIf You Don't Live Near Yellowstone - SFGATE - June 12th, 2025 [June 12th, 2025]
- 'White Lotus'-Worthy Santa Monica Home Where Charlie Chaplin Stored His Fire Truck Collection Hits the Market for $12.5 Million - SFGATE - June 12th, 2025 [June 12th, 2025]
- Ding-Dong, The Price Just Dropped 20% on the Eufy Video Doorbell E340 - Yahoo - June 12th, 2025 [June 12th, 2025]
- This video doorbell camera successfully replaced my Ring - with no subscription fees required - ZDNET - June 12th, 2025 [June 12th, 2025]
- Inside Lavish Homes of AI Guru Lucy Guo, the 30-Year-Old Who Dethroned Taylor Swift as World's Youngest Self-Made Woman Billionaire - SFGATE - June 12th, 2025 [June 12th, 2025]
- They Deepfaked Through the Bathroom Window: How Cybercriminals Are Targeting Executives & Key Personnel at Home - Security Boulevard - June 12th, 2025 [June 12th, 2025]
- Watch out Ring this new video doorbell from IMOU has a rotating camera to track visitors, and AI to detect loiterers - TechRadar - June 12th, 2025 [June 12th, 2025]
- 7 smart home gadgets that watch your house for you so you can actually enjoy your vacation - Tom's Guide - May 28th, 2025 [May 28th, 2025]
- Home Security Cheat Sheet: I Gathered All Our Best Expert Advice - CNET - May 28th, 2025 [May 28th, 2025]
- I replaced my Ring with this outdoor security camera - and there's no subscription required - ZDNET - May 28th, 2025 [May 28th, 2025]
- Radar-Based Home Security System Using RD-03D and ESP32-C6 - Hackster.io - May 28th, 2025 [May 28th, 2025]
- The Smart Video Doorbell I Recommend to Everyone Is Still On Sale After Memorial Day - CNET - May 28th, 2025 [May 28th, 2025]
- Protect your home! Save 60% on SimpliSafe security systems with this Memorial Day deal - USA Today - May 28th, 2025 [May 28th, 2025]
- Memorial Day Sales Have the Budget Security Cam I Recommend to Anyone for 50% Off - CNET - May 28th, 2025 [May 28th, 2025]
- One of the Best Security Cam Deals From Memorial Day Is Somehow Still Around - extremetech.com - May 28th, 2025 [May 28th, 2025]
- House Passes Trump's 'Big, Beautiful Bill'but Federal Land Sale Provision Is Axed - SFGATE - May 28th, 2025 [May 28th, 2025]
- The Wyze cam that pans, tilts, and zooms is only $30 at Amazon this weekend - Mashable - May 28th, 2025 [May 28th, 2025]
- These tiny Blink outdoor security cameras will protect your home day and night, and they're half price at Best Buy for Memorial Day - TechRadar - May 28th, 2025 [May 28th, 2025]
- Safety First, Then Savings: Early Memorial Day Deals on Home Security Cameras and Video Doorbells - PCMag - May 20th, 2025 [May 20th, 2025]
- Mom checks home cam at 1:17am, shocked to see who's in living room - Newsweek - May 20th, 2025 [May 20th, 2025]
- Maryland Flippers Are Averaging Nearly $150K in ProfitsHeres Where Theyre Finding Success - SFGATE - May 20th, 2025 [May 20th, 2025]
- The best home locks, doorbells and alarms to deter burglars - The Times - May 20th, 2025 [May 20th, 2025]
- He Offered To Help His Sister-in-Law Take Care Of Her Daughter, But When She Installed Security Cameras To Watch His Every Move, He Couldnt Shake The... - May 20th, 2025 [May 20th, 2025]
- Pets with a toolkit: Protection dogs train to handle burglars as sports stars boost home security - Herald Bulletin - May 20th, 2025 [May 20th, 2025]
- The Best MyQ Home Security Devices To Help Give You Peace Of Mind - Forbes - March 17th, 2025 [March 17th, 2025]
- How Home Alarm System Brand ADT Learned To Love CTV - AdExchanger - March 17th, 2025 [March 17th, 2025]
- Teyana Taylor Will Receive 4 Homes Worth More Than $10 Million as Part of Multimillion-Dollar Divorce Settlement With Iman Shumpert - SFGATE - March 17th, 2025 [March 17th, 2025]
- This solar-powered outdoor camera might be the only one you'll ever need - ZDNet - March 17th, 2025 [March 17th, 2025]
- Is There a Security Camera That Works Without Wi-Fi? - Security.org - March 17th, 2025 [March 17th, 2025]
- Lily Allen and David Harbour Turned Their Brooklyn Home Into 'Weird' Floral WonderlandSo, What Becomes of It Amid Rumored Split? - SFGATE - February 8th, 2025 [February 8th, 2025]
- Caught on camera: Bixby woman nearly walks in on masked burglar in her home - news9.com KWTV - February 8th, 2025 [February 8th, 2025]
- Smart Lock Market to Attain Valuation of US$ 15.42 Billion by 2032 - Yahoo Finance - February 8th, 2025 [February 8th, 2025]
- Travis Kelce goes full John Wick on home security after burglary - Marca English - February 8th, 2025 [February 8th, 2025]
- Google Nest Security Camera With Floodlight Wont Stay This Cheap for Long, First Price Drop in Months - Gizmodo - February 8th, 2025 [February 8th, 2025]
- The 3 Best Smart Water-Leak Detectors of 2025 | Reviews by Wirecutter - Wirecutter, A New York Times Company - February 8th, 2025 [February 8th, 2025]
- Oil Billionaire Bill Koch Lists His Eco-Friendly 'Once in a Lifetime' Aspen Estate for $125 MillionMore Than Four Times What He Paid - SFGATE - February 8th, 2025 [February 8th, 2025]
- Home Security Systems Market is anticipated to project robust - openPR - February 8th, 2025 [February 8th, 2025]
- The best Wyze Cam alternative I've tested is only $20 with this deal - ZDNet - February 8th, 2025 [February 8th, 2025]
- Eufy SoloCam S340 review: a solar-powered and fully wireless outdoor security camera - The Independent - February 8th, 2025 [February 8th, 2025]
- Smart Lock Buying Guide: Picking Locks the Right Way - CNET - February 8th, 2025 [February 8th, 2025]
- Trump's Homeland Security pick pressed on domestic terrorism in hearing - NPR - January 21st, 2025 [January 21st, 2025]
- Man watches in horror from security camera as California wildfire engulfs his home: 'All I could do' - Fox Weather - January 21st, 2025 [January 21st, 2025]
- Unprecedented video shows falling meteorite, records sound of impact - For The Win - January 21st, 2025 [January 21st, 2025]
- HomeKit Weekly: Combat dry winter air with the SwitchBot Smart Evaporative Humidifier - 9to5Mac - January 21st, 2025 [January 21st, 2025]
- The Google Home app is getting a big update, and it's good news for your security - TechRadar - January 21st, 2025 [January 21st, 2025]
- 6 ways Reolink's CES 2025 gadgets upped the ante for every other security camera this year - Android Police - January 21st, 2025 [January 21st, 2025]
- No Monthly Fee, the Eufy Security Floodlight Cam Is Now More Affordable Than Ever - Gizmodo - January 21st, 2025 [January 21st, 2025]
- Sound of Meteorite Hitting Earth Recorded by Security Camera Moments After Couple Left Home to Walk Their Dogs - PEOPLE - January 21st, 2025 [January 21st, 2025]
- Attempted burglary in Cranford highlights importance of home security - News 12 New Jersey - January 3rd, 2025 [January 3rd, 2025]
- Matthew Stafford had police inspect his home for potential security flaws amid burglaries - Rams Wire - January 3rd, 2025 [January 3rd, 2025]
- The Ring Stick Up Cam Pro drops to its all-time low price! - Android Authority - January 3rd, 2025 [January 3rd, 2025]
- Dallas Mavericks star Luka Doncic's home targeted in string of home burglaries - CBS News - January 3rd, 2025 [January 3rd, 2025]
- How Wireless Doorbell Kits Are Changing Home Security for the Better - openPR - January 3rd, 2025 [January 3rd, 2025]
- What UHNWs can learn about home security from 10 million London mansion heist - Spear's WMS - January 3rd, 2025 [January 3rd, 2025]
- Luxury Turns to Loss: Shafira Huangs Shocking Theft - Qhubo - January 3rd, 2025 [January 3rd, 2025]
- Home Tech Companies Are Peddling 'Affectionate Intelligence.' Should We Fall for It? - CNET - January 3rd, 2025 [January 3rd, 2025]
- The Best of Smart Home in 2024: The 10 Articles You Read the Most - How-To Geek - January 3rd, 2025 [January 3rd, 2025]
- The Top Home Security Mistakes to Stop Making in 2025 - CNET - January 3rd, 2025 [January 3rd, 2025]
- MagSafe Monday: LISEN delivers the strongest MagSafe magnet Ive found for the car - 9to5Mac - January 3rd, 2025 [January 3rd, 2025]
- The best floodlight and security camera combo I've tested is $70 off - ZDNet - January 3rd, 2025 [January 3rd, 2025]
- I invested in a subscription-less video doorbell, and it's paying off for my smart home - ZDNet - January 3rd, 2025 [January 3rd, 2025]
- NBA follows NFL in warning players on burglaries - ESPN - November 29th, 2024 [November 29th, 2024]
- Find heavily discounted security cameras and video doorbells ahead of Black Friday - Mashable - November 29th, 2024 [November 29th, 2024]
- This Floodlight Camera Has My Backyard Covered, and It's Under $100 for Black Friday - Lifehacker - November 29th, 2024 [November 29th, 2024]
- Get the ultimate home security this holiday season with Wyze starting at $17 - New York Post - November 29th, 2024 [November 29th, 2024]
- This Is the Best Black Friday Deal for an All-Purpose Security Cam I've Ever Seen - CNET - November 29th, 2024 [November 29th, 2024]
- NBA memo to players urges increased vigilance regarding home security following break-ins - Ashland Daily Press - November 29th, 2024 [November 29th, 2024]
- Find discounted security cameras and video doorbells ahead of Black Friday - Mashable - November 29th, 2024 [November 29th, 2024]
- The 4 Most Common Package Scams in 2024 -- and How to Stop Them - CNET - November 29th, 2024 [November 29th, 2024]
- Keep Your Home Protected During Your Holiday Travel With Up to 60% Off Blink Outdoor 4 Cams - CNET - November 21st, 2024 [November 21st, 2024]
- Editor's Note: Whats Old is New and Innovative Again? - SecurityInfoWatch - November 21st, 2024 [November 21st, 2024]
- Beef Up Your Home Security and Get Up to 77% Off With These Arlo Black Friday Deals - CNET - November 21st, 2024 [November 21st, 2024]
- Ive ditched my Nest Cams for a Chinese smart security brand you probably havent heard of - The Ambient - November 21st, 2024 [November 21st, 2024]
- Boost Your Home's Security With the Outdoor Roku Cam, Down to $20 for Black Friday - CNET - November 21st, 2024 [November 21st, 2024]
- Home Security Experts Share Important Insights About the Travis Kelce and Patrick Mahomes Burglaries - House Beautiful - November 21st, 2024 [November 21st, 2024]