Find your exact model
The brand alone isn't enough — the exact model and version number on the label decide whether you're affected.
We keep genuine current warnings, fixes, routers that are no longer updated, and recycled old news stories clearly separate. Slow Wi-Fi on its own is not a sign your router has been hacked.
The brand alone isn't enough — the exact model and version number on the label decide whether you're affected.
A router that's too old to get updates might never be fixed, even for a known problem.
Update the firmware or replace the router. Don't share your home IP address online, install unofficial software, or turn off your firewall.
What this means for you: use the coloured tag to see how serious each warning is, then open it to check whether your exact model and firmware are affected before doing anything.
DNS hijacking used to redirect traffic and harvest credentials.
What to doUpdate supported firmware, replace end-of-life hardware, and check DNS and admin settings.
NCSC ↗High23 April 2026 · China-linked covert networks · ActiveCompromised edge devices used to hide attacks against critical sectors.
What to doPatch, disable unnecessary remote management, and use strong unique admin credentials.
NCSC / CISA ↗High2 June 2025 · AyySSHush persistent SSH backdoor · Patched / investigateKnown vulnerabilities plus weak credentials were combined to add persistent SSH access that survives reboots.
What to doInstall the latest ASUS firmware, inspect for unknown SSH keys or access, and replace unsupported models.
CSA Singapore ↗PatchOngoing · Multiple CVEs; Quad7-style botnet activity on end-of-life units · Vendor registerOlder unsupported routers have appeared in botnets and credential attacks.
What to doCheck your hardware version, apply the official patch, and retire end-of-life units.
TP-Link ↗HighJanuary 2025 · Ficora and Capsaicin botnets · End of lifeLegacy models actively targeted through old vulnerabilities and recruited into botnets.
What to doReplace affected end-of-life models rather than relying on a reboot.
MyCERT / D-Link ↗PatchOngoing · Published vulnerabilities including code execution and denial of service · Vendor registerCode execution, information disclosure, denial of service, buffer overflow and WLAN-driver issues.
What to doMatch the exact model to its advisory and use official firmware only.
DrayTek PSIRT ↗Historical6 May 2021 · Ageing firmware and weak defaults · HistoricalA Which? investigation reported weaknesses in several old ISP-supplied models.
What to doAsk whether your exact model still receives updates and request replacement if it does not.
Mirror / Which? coverage ↗End of support6 May 2024 · Security updates ending · End of lifeReports described provider notices that some older hubs would no longer receive security updates.
What to doConfirm the exact model and notice, change the admin password, and replace unsupported equipment.
The Sun / provider notices ↗Unknown DNS servers, admin settings you didn't change, remote access you didn't turn on, new forwarding rules, or an official notice naming your exact model.
Slow Wi-Fi, pop-up adverts, or one infected laptop don't on their own prove your router's been hacked — check each possible cause separately.
Use the official app or the router's own settings page, update the firmware, change the admin password, turn off remote access you don't use, and replace anything too old to update.
We trust the router maker's own advisory or a national cyber-security agency first, and only use news coverage to add context — never as the main source.
Newspaper headlines are checked against the original advisory and are never used on their own to make a brand-wide claim. Register checked 17 August 2026.