by

FCC lets foreign routers live a bit longer

The Federal Communications Commission has blinked on its foreign router crackdown after realising millions of unpatched foreign boxes would be a security bonfire.

It will now allow vendors to continue issuing software and firmware updates for already-deployed devices in the US until at least January 2029.

The decision tweaks a March 2026 FCC ruling that bans foreign manufacturers from selling new consumer router models in the US. The ban does not cover models the agency had already approved.

The FCC cited national security worries as its main excuse for adding foreign-made small office and home office routers to its prohibited equipment list. The agency said adversaries, including nation-state groups, had used routers to help attacks against US organisations.

Under the original ruling, foreign manufacturers could provide only limited maintenance and security patches to US customers until March 2027. In a public note on 8 May, the FCC stretched that deadline to at least January 2029.

It widened the scope of permitted updates too, which is rather useful if you do not fancy running your network on a slowly rotting plastic box. The FCC will now allow foreign manufacturers to provide more than minor security fixes and tweaks.

They can issue bigger software and firmware updates that affect router functionality, which previously needed extra FCC review. The agency said the changes were meant to keep already deployed foreign-made consumer routers in the US safe.

That is a sizeable reprieve for millions of US consumers and small and medium-sized businesses using the affected gear. It gives them more time to find alternatives, assuming such alternatives can be found without buying another foreign-made router.

Analysts have noted that almost all consumer-grade routers currently available in the US are manufactured abroad. Infosec professionals had warned that the ban could leave users stuck with ageing and unsupported devices. That would have made them more vulnerable to attack.

Many security bods have said the real router problem is not simply where the kit is made.

The nastier risks come from default passwords, sloppy configurations and owners who treat security patches as optional decoration.

The extension through 2029 does not seriously change the import ban on foreign-made consumer routers.

It does give users more breathing room before the policy becomes a support nightmare.

“This waiver significantly alleviates the most pressing fears tied to the initial ban by preventing a sudden and dangerous security vacuum,” Soroko said.

Keeper Security chief information security officer Shane Barney said organisations using affected devices should keep the change in perspective. A hard ban on updates would have left deployed devices without any path to security patches or vulnerability fixes. That would have dumped vendors and users in an impossible position.

 

 

TOPICS:
cybersecurity  ·  FCC  ·  firmware updates  ·  foreign-made hardware  ·  Keeper Security  ·  network security  ·  routers  ·  Sectigo  ·  zero trust

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews