Most people never update their networking equipment, and cybercriminals know it

Most people never update their networking equipment, and cybercriminals know it

Published Aug 14, 2026, 8:00 AM EDT Maker, meme-r, and unabashed geek, Joe has been writing about technology since starting his career in 2018 at KnowTechie. He's covered everything from Apple to apps and crowdfunding and loves getting to the bottom of complicated topics. In that time, he's also written for SlashGear and numerous corporate clients before finding his home at XDA in the spring of 2023. He was the kid who took apart every toy to see how it worked, even if it didn't exactly go back together afterward. That's given him a solid background for explaining how complex systems work together, and he promises he's gotten better at the putting things back together stage since then. With a few notable exceptions, modern technology updates itself automatically. Your phone updates monthly, Windows wants to reboot to install updates at the least convenient times, and even robot vacuums update their firmware without asking first. You know what rarely does? The router that those update files flow through. At least for most people. My homelab changes router settings constantly, and the UniFi and OPNsense boxes get updated every week as part of routine maintenance. But my current home gateway is an eero Pro 6E, which automatically updates every week or two without asking me. The router manufacturers have decided that users can’t be trusted to keep things updated or replace those aging Wi-Fi routers, and you know what, they’re right. Nobody updates their router and the numbers prove it The maddening thing is they know how, they just don't Surveys are to be taken with a grain of salt, but they’re still one of the best indicators of trends we have. And a 2025 survey of 3,242 internet users found that 84% have never updated their router’s firmware. On top of that, 81% say they never changed the default admin password, 47% have never changed the factory defaults, and I just heard thousands of sysadmins screaming. But it’s not just 2025; things have actually improved slightly since 2018, when 86% had never updated their router firmware. We expect the thing linking us to the internet to have inherent security, but historically, that’s not been the case. In 2018, the American Consumer Institute tested 186 consumer routers and found that 83% shipped with known vulnerabilities, averaging 12 critical flaws per device. Those are just the ones that are trivial to abuse. They found over 32,000 vulnerabilities in total, which is staggering. That expectation might explain why the 2025 survey showed that most respondents knew how to change settings and update firmware, but didn’t do it or understand why it mattered. It’s a motivation issue, not a skill one, and I can’t blame manufacturers for automating the process. Criminals turned forgotten routers into a $46 million business Unpatched network gear gets swept up in days In May 2025, the FBI published a public service announcement warning that criminals are actively hunting end-of-life routers. These were being hijacked by malware from the TheMoon family, which doesn’t need your password to take over; it just needs an open port to send its script to your device. From that point on, your router is a residential proxy, a clean, boring, home-broadband IP address that other people’s crimes get routed through. It’s not a hypothetical threat; it’s a verified one, with the Justice Department taking down a proxy-for-hire network in the same month that prosecutors say made $46 million for the four men indicted for running it. And just in case your security model is “eventually someone might stumble across my router,” it’s time to adjust that. A fresh TheMoon variant circulated in 2024 that compromised 6,000 Asus routers in under 72 hours, and, by the end, a rough tally of 40,000 devices across 88 countries. Mass scanning is cheap, automated, and constant, and your unpatched router is exactly what it’s looking for.​​​​​​​ Nation-state actors also go looking for old routers The FBI ended up wiping routers the owners forgot existed Scary as they sound, fraud proxies are the low end of cybercriminals' operations. In early 2024, CISA and the FBI revealed that a Chinese state-sponsored group had been quietly taking over small-office and home routers to create the KV Botnet since 2021. It was designed to camouflage attacks on US critical infrastructure as ordinary American home traffic, and it worked. The cleanup process could have been long, or even impossible, if it relied on contacting individual users. Instead, the FBI obtained a court order and remotely deleted the malware from infected routers, because the owners had no idea their hardware was compromised. Imagine a problem so vast that the federal government had to step in to patch it.​​​​​​​ The newer your router, the less you have to worry Auto-updates can't save the router in your closet, though I’m not saying modern routers are more secure, although they generally are. But one thing has changed in the last decade: mesh Wi-Fi network equipment updates itself, and many other standalone routers do the same. That means people who never manually update their firmware don't have to learn, and your ISP router gets patched centrally as well, because the ISP cares about its own network. If your router is relatively new, “I never update my router” and “my router is unpatched” are no longer the same thing. However, none of the attacks mentioned earlier would have been stopped by auto-updates or even by an owner clicking the update button. They all targeted end-of-life hardware, the stuff manufacturers no longer support or update. The UK now bans universal default passwords, and the EU has turned security updates into a legal obligation rather than a market force.​​​​​​​ Check your router's life expectancy before the criminals do There’s one practical takeaway from all of this. Find your router’s model number from the UPC sticker, and look up the manufacturer’s end-of-life list to see if you still get firmware updates. If it dates from the early 2010s, doesn’t do automatic updates, or the support pages have vanished, the next update it receives is the e-waste recycling bin at the local dump. Then it’s time to upgrade to a good Wi-Fi router, which will pay for itself in security and not having to remember to update the firmware. Criminals have already done their shopping homework; now it’s your turn.​​​​​​​ OPNsense Build a home router that keeps getting updates with OPNsense.

Original Source

Read the full article at Xda-developers →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.