Router security · checked against original sources

Is your router a security risk?

We keep genuine current warnings, fixes, routers that are no longer updated, and recycled old news stories clearly separate. Slow Wi-Fi on its own is not a sign your router has been hacked.

01

Find your exact model

The brand alone isn't enough — the exact model and version number on the label decide whether you're affected.

02

Check it's still supported

A router that's too old to get updates might never be fixed, even for a known problem.

03

Do the sensible thing

Update the firmware or replace the router. Don't share your home IP address online, install unofficial software, or turn off your firewall.

Check my router →Is my router too old? →

What this means for you: use the coloured tag to see how serious each warning is, then open it to check whether your exact model and firmware are affected before doing anything.

Critical7 April 2026 · APT28 / Russian GRU DNS hijacking · Active

Vulnerable TP-Link and MikroTik routers

DNS hijacking used to redirect traffic and harvest credentials.

What to do

Update supported firmware, replace end-of-life hardware, and check DNS and admin settings.

NCSC
High23 April 2026 · China-linked covert networks · Active

SOHO routers and smart devices

Compromised edge devices used to hide attacks against critical sectors.

What to do

Patch, disable unnecessary remote management, and use strong unique admin credentials.

NCSC / CISA
High2 June 2025 · AyySSHush persistent SSH backdoor · Patched / investigate

ASUS consumer routers

Known vulnerabilities plus weak credentials were combined to add persistent SSH access that survives reboots.

What to do

Install the latest ASUS firmware, inspect for unknown SSH keys or access, and replace unsupported models.

CSA Singapore
PatchOngoing · Multiple CVEs; Quad7-style botnet activity on end-of-life units · Vendor register

TP-Link routers and smart devices

Older unsupported routers have appeared in botnets and credential attacks.

What to do

Check your hardware version, apply the official patch, and retire end-of-life units.

TP-Link
HighJanuary 2025 · Ficora and Capsaicin botnets · End of life

Legacy D-Link routers

Legacy models actively targeted through old vulnerabilities and recruited into botnets.

What to do

Replace affected end-of-life models rather than relying on a reboot.

MyCERT / D-Link
PatchOngoing · Published vulnerabilities including code execution and denial of service · Vendor register

DrayTek Vigor routers, access points and switches

Code execution, information disclosure, denial of service, buffer overflow and WLAN-driver issues.

What to do

Match the exact model to its advisory and use official firmware only.

DrayTek PSIRT
Historical6 May 2021 · Ageing firmware and weak defaults · Historical

Older EE, Sky, TalkTalk, Virgin Media and Vodafone routers

A Which? investigation reported weaknesses in several old ISP-supplied models.

What to do

Ask whether your exact model still receives updates and request replacement if it does not.

Mirror / Which? coverage
End of support6 May 2024 · Security updates ending · End of life

Sky Hub 3 or earlier and selected NOW hubs

Reports described provider notices that some older hubs would no longer receive security updates.

What to do

Confirm the exact model and notice, change the admin password, and replace unsupported equipment.

The Sun / provider notices
Signs worth checking

Unknown DNS servers, admin settings you didn't change, remote access you didn't turn on, new forwarding rules, or an official notice naming your exact model.

What this doesn't mean

Slow Wi-Fi, pop-up adverts, or one infected laptop don't on their own prove your router's been hacked — check each possible cause separately.

Safe first steps

Use the official app or the router's own settings page, update the firmware, change the admin password, turn off remote access you don't use, and replace anything too old to update.

How we check our facts

We trust the router maker's own advisory or a national cyber-security agency first, and only use news coverage to add context — never as the main source.

Show our step-by-step checking order
  1. 1Current regulator or government cyber advisory
  2. 2Current official ISP or router-vendor support / PSIRT bulletin
  3. 3Standards body or primary technical research
  4. 4Reputable industry publication
  5. 5Mainstream newspaper report
  6. 6Moderated vendor community
  7. 7Reddit or social post — investigation lead only

Newspaper headlines are checked against the original advisory and are never used on their own to make a brand-wide claim. Register checked 17 August 2026.