Site navigation

Could Your Outdated Router Pose A Security Risk?

Ross Kelly

,

router security

Router security flaws could put up to 7.5 million people across the UK at risk.

Millions of UK internet users could be at risk of cyber-attacks by using outdated routers, according to an investigation from Which?

A study by the consumer rights group found that router models provided by a host of Britain’s top internet service providers, including Sky, Virgin Media and EE, contain serious security flaws.

In total, researchers investigated 13 outdated router models. Two-thirds of those were found to have flaws that would see them fail to meet impending government requirements to bolster connected device security.

With millions across the country working from home, the consumer group warned that a sizeable portion of the population is at risk due to substandard security.

“These security risks could potentially affect around 7.5 million people, based on the number of respondents who said they were using these router models,” Which? said.

Within this group, around six million people could be using a router that hasn’t been updated since 2018 or earlier, the report warned. Similarly, anywhere up to 2.4 million users also haven’t had a router upgrade in the last five years.

This means that many devices will not have been receiving regular security updates that are crucial in combating cybercriminals and hackers.

Concerning Discovery

Some of the main problems uncovered by tests on older router models included weak default passwords and a lack of firmware updates, the latter of which is vital for both security and performance.

Tests also revealed local network vulnerability issues with the EE Brightbox 2. Researchers warned this concerning vulnerability could put customers at huge risk.

“This could give a hacker full control of the device, and for example allow them to add malware or spyware, although they would have to be on the network already to attack,” Which? said.

Other devices from some of the country’s top ISPs were also found to have serious flaws.

The Sky SR101 and SR102 routers, as well as Virgin Media’s Super Hub and Super Hub 2 products, were all found to be lacking in regard to password security and the frequency of updates.

Products from BT, including the BT Home Hub 3B, 4A and 5B, all passed rigorous testing by experts along with the Plusnet Hub Zero 2704N router, Which? noted.


Recommended


Virgin Media contested the results of the study and noted that the majority of its customers now use the latest routers provided.

“We do not recognise or accept the findings of the Which? research – nine in ten of our customers are using the latest Hub 3 or Hub 4 routers,” a spokesperson said.

“The safety and security of our customers is always a top priority, and we have robust processes in place to protect them by rolling out security patches and firmware updates as well as issuing customer communications where necessary,” the company added.

A spokesperson for EE, which is part of BT Group, insisted that all routers are “constantly monitored for possible security threats” and are “updated when needed”.

“These updates happen automatically so customers have nothing to worry about,” they commented.

Impending Regulation

The UK Government plans to introduce new laws aimed at ensuring all smart devices meet stringent security requirements.

These changes will require manufacturers to tell customers for how long smart devices will receive security software updates.

Additionally, new regulations will impose a ban on manufacturers using universal default passwords that are often pre-set and easily guessable.

Which? warned that many consumers leave default passwords unchanged on their internet routers because they are “not aware of the security risks of doing so”.

Kate Bevan, computing editor at Which? said the consumer rights group welcomes government changes, which are positive step in protecting consumers.

“Proposed new government laws to tackle devices with poor security can’t come soon enough – and must be backed by strong enforcement,” she said.

“Given our increased reliance on our internet connections during the pandemic, it is worrying that so many people are still using out-of-date routers that could be exploited by criminals,” Bevan added.

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data