Is Your Router Leaving Your Internet-Connected Devices Vulnerable to Hackers?

Jun 19, 2018 | Security

By Louis Creager, Security Analyst, zvelo

Ubiquitous as they are in our households, relatively few consumers are conscious of the firmware running on their home router – let alone the urgency of keeping that firmware up-to-date. A study by Ubuntu, an open source OS, has found that only 31% of consumers execute firmware updates on their routers when they become available, and that four in ten never update firmware on their devices at all.

Unfortunately, what these consumers don’t know can indeed hurt them (and others). Router exploits left open by unpatched firmware don’t just put the router itself at risk; rather, a hacked router can easily be used to target and infect any other hosts on that user’s home network from laptop and desktop computers to mobile and IoT devices.

Router vulnerabilities continue to pose an especially simple target for hackers to take advantage of. As we demonstrated in a recent test, an unpatched router can be hacked in less than a minute, without any need for the router’s password or credential authentication whatsoever. In the specific case we investigated, the router’s in-browser “Forgotten Admin Password” page even confirmed the firmware version prior to gaining access, letting a hacker know with certainty that the exploit will work.

Weak routers allow a hacker armed with an advanced exploit kit to simply enter an attack URL containing certain code, and then Telnet into an authenticated shell within moments. From there, hackers can run any command they want. They can make the router non-operational. They can erase router firmware, and replace it with their own malicious code. They can also redirect the domain name service the router uses, and send users connecting to the internet to any fake website they wish (making identity theft an all-too-easy proposition).

However, the arguably scarier risk here is in losing all control of devices connected to the router. As smart home devices fill our lives, it’s not hard to imagine hackers with ill intent repurposing those all-too-convenient connected devices to create haunted house scenarios. Consumers may quickly become a lot more interested in performing router firmware updates when they understand it means preventing strangers from flicking their lights on and off, messing with their thermostats, controlling their kitchen appliances, or perhaps even making smart fitness watches count their daily steps backward – real creepy horror movie stuff.

This kind of mischief aside, a more common (and also a more consequential) scenario is router exploits resulting in at-risk connected devices becoming enlisted in a massive botnet – turned to sinister purposes such as distributed denial of service (DDoS) attacks. The threat of this happening to a consumer’s smart devices is all too real – in an experiment conducted by The Atlantic, a fake web toaster was hacked just an hour after going online.

How do hackers know how and when to take advantage of these devices? The real work of building botnets is done by software that automatically scours the web for unsecured devices. With this malicious software, hackers can gain control over these devices, or even create backdoors to them by secretly installing code that enables future access. Hackers can then treat those devices as sleeper cells prepared to cause future mayhem whenever commanded.

When a hacker activates one of these botnets for a DDoS attack, it can not only cause your compromised devices to ignore their regular duty (making fake toast, etc.), but will also begin misusing your bandwidth – alongside thousands or millions of other hacked connected devices – in an attempt to knock a targeted site or entity offline by overloading it with requests. Amazon, Twitter, and even the country of Liberia have been victims in the past year of such botnet attacks, largely powered by exploited devices.

This is why it’s so important to keep the firmware on routers and other connected devices patched and up-to-date. With threats ranging from identity theft to household danger to losing connectivity in entire countries, failure to do so puts both yourself and others at risk.

zvelo - Louis Creager Headshot

Louis Creager is a Security Analyst at zvelo, a provider of cybersecurity solutions for web content, traffic and devices.

 

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more