homehome Home chatchat Notifications


Outdated WiFi routers may pose a huge security risk to millions of people

If you haven't updated your router in years you're not alone -- and that's not good.

Tibi Puiu
July 6, 2021 @ 6:04 pm

share Share

Routers have become essential in billions of homes. But how often do you think about their security?

Credit: Pixabay.

After plugging in a home router, most people don’t give it much second thought until it breaks down or the WiFi doesn’t work anymore for some reason. However, in a world where our devices are becoming increasingly connected with each other and where more of us are working from home, even seemingly benign WiFi routers could pose important security threats. According to a recent assessment by consumer watchdog Which?, it’s estimated that about six million people have not updated their router since 2018 or earlier — and that’s just in the UK.

Woefully ill-prepared

According to security experts, your typical home router is woefully ill-prepared in the face of a cyberattack. Most home routers have weak default passwords, lack critical firmware updates, and feature network vulnerabilities such as those involving EE’s Brightbox 2 (this could give a hacker complete control over the device).

The cybersecurity researchers examined 13 router models provided by EE, Sky, and Virgin Media. Two-thirds of these devices were found to be flawed, including the Sky SR101 and SR102; Virgin Media Super Hub and Super Hub 2; and the TalkTalk HG635, HG523a, and HG533.

The only routers that passed all security tests were those from BT, including the Home Hub 3B, 4A and 5B, and Plusnet’s Hub Zero 270N. However, BT had a critical vulnerability in its Brightbox 2 router supplied by EE, which is part of BT Group.

Fortunately, modern spectrum compatible routers have device-specific default passwords and automatically perform firmware updates. However, older models will suffer from the problems identified in this raport.

BT Group, Virgin Media, and TalkTalk denied the validity of the findings each claiming that old and outdated routers comprise only a small fraction of their userbase. However, other security research groups came to similar conclusions in the past.

“We have been trying to convince one of the ISPs in question to fix a critical security flaw that allows several million of their customer routers to be remotely hijacked and gain access to home networks,” Pen Test Partners security consultant Ken Munro told the BBC.

“We reported the issue over a year ago – but they have procrastinated multiple times.”

Around 7.5 million internet users in the UK were affected by the vulnerabilities, with no updates since 2018 and even 2016 in some cases, the report found. Six million British households used outdated equipment provided by the internet providers, the authors added.

“Internet service providers should be much clearer about how many customers are using outdated routers and encourage people to upgrade devices that pose security risks,” said Which? computing editor Kate Bevan.

In order to solve this problem, a topdown approach may prove the best. Most broadband consumers are not particularly tech-savvy, which is why the responsibility for ensuring their devices are secure must fall on the internet provider.

The UK government is currently drafting legislation that will broadly regulate smart devices, but which will also include rules such as banning default passwords from being preset on devices and requiring manufacturers to inform consumers of how long their devices will receive security software updates. Although the study focused on the UK alone, it’s hard to believe that other countries would fare much better.

share Share

The world’s largest wildlife crossing is under construction in LA, and it’s no less than a miracle

But we need more of these massive wildlife crossings.

Your gold could come from some of the most violent stars in the universe

That gold in your phone could have originated from a magnetar.

Ronan the Sea Lion Can Keep a Beat Better Than You Can — and She Might Just Change What We Know About Music and the Brain

A rescued sea lion is shaking up what scientists thought they knew about rhythm and the brain

Did the Ancient Egyptians Paint the Milky Way on Their Coffins?

Tomb art suggests the sky goddess Nut from ancient Egypt might reveal the oldest depiction of our galaxy.

Dinosaurs Were Doing Just Fine Before the Asteroid Hit

New research overturns the idea that dinosaurs were already dying out before the asteroid hit.

Denmark could become the first country to ban deepfakes

Denmark hopes to pass a law prohibiting publishing deepfakes without the subject's consent.

Archaeologists find 2,000-year-old Roman military sandals in Germany with nails for traction

To march legionaries across the vast Roman Empire, solid footwear was required.

Mexico Will Give U.S. More Water to Avert More Tariffs

Droughts due to climate change are making Mexico increasingly water indebted to the USA.

Chinese Student Got Rescued from Mount Fuji—Then Went Back for His Phone and Needed Saving Again

A student was saved two times in four days after ignoring warnings to stay off Mount Fuji.

The perfect pub crawl: mathematicians solve most efficient way to visit all 81,998 bars in South Korea

This is the longest pub crawl ever solved by scientists.