There's yet another really good reason to patch your router now

Switch broadband providers
(Image credit: Kittichai Boonpong / EyeEm)

There are hundreds of vulnerabilities plaguing routers of all shapes and sizes, and most of them have not been patched, new analysis from Kaspersky has warned.

The company’s report says that in 2021, there had been a total of 506 new vulnerabilities discovered, out of which 87 were deemed as critical. Of those, a third (almost 30) have not been addressed by their respective vendors, whatsoever, while another 26% were important enough to only get an advisory.

Sometimes, these advisories are followed up with a patch, the researchers are saying, but most of the time, they just tell potential victims to reach out to customer support. 

Image

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

The absolute worst year for the discovery of critical flaws in router endpoints was 2020 - the year of the Covid-19 pandemic, and the subsequent rush to remote working. That year, Kaspersky says, 603 new vulnerabilities were discovered, almost three times as many as the year before (207).

These two things are correlated, the researchers further claim, as remote working put most employees at the mercy of their (unpatched and unprotected) home routers. While most workers these days know relatively well how to protect their computers, laptops, and mobile devices, they’re clueless what to do with their routers. 

According to figures from Broadband Genie, half (48%) have never changed their router’s settings, including the default login credentials, and their Wi-Fi password. Three quarters (73%) don’t think it’s necessary, while 20% don’t know how to change these things. 

To keep any internet-connected device secure, there are a number of things a person (or company) can do: keep both firmware, and software, updated to the latest version, at all times; install a strong antivirus solution, as well as a firewall; activate multi-factor authentication on any services available, and use a Virtual Private Network (VPN) service. 

For routers, specifically, users should always use WPA2 encryption, disable remote access to the router, select a static IP address, disable DHCP, and use a MAC filter.

Via: VentureBeat

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
cables going into the back of a broadband router on white background
Netgear urges users to patch major router security issues now
An image of network security icons for a network encircling a digital blue earth.
Industrial networks exposed to attack by faulty Moxa devices
China
Juniper patches security flaws which could have let hackers take over your router
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
IoT’s botnet problem is up 500% – three things admins must do now
Security
Zyxel says it won’t patch security flaws in its old routers
Cyber-security
Juniper Session Smart routers have a critical flaw, so patch now
Latest in Pro
ai quantization
Shadow AI: the hidden risk of operational chaos
Digital clouds against a blue background.
Navigating the growing complexities of the cloud
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand