Skip to main content
Find a broadband deal
Fix my broadband

More vulnerabilities out there — Have you updated your broadband router’s firmware?

Photo of back of a router

Most users in the UK will receive their router from their broadband provider, who is also responsible for managing it and keeping it secure. Indeed, unless you’re a technically minded user (and possibly even if you are one), this is by far the easiest option for you as you have one less device to manage. If you’re a Virgin Media, BT, Sky or TalkTalk user, this will probably be the case (unless you’ve replaced it yourself).

There are reasons to use your own router. For example, may broadband-provider supplied routers block ICMP Echo Requests (also known as WAN Ping) which is required to use our Broadband Quality Monitor tool. (Quick reminder — if you need more than 5 monitors, you can e-mail us with details of what you want to monitor). Sometimes it’s possible to enable this by a setting or advanced firewall modes, but in many cases it’s not possible.

If you bought your own router, be it from Amazon or your broadband provider, you may need to ensure it’s updated. This is important as there have been recent security vulnerabilities in Asus and Draytek routers. We should stress however that these issues can happen with any brand.

What you also need to be aware of is how long your broadband router is supported. We recently saw this ourselves with a TP-link router. When clicking ‘update’ it confirmed that it had the latest firmware. This was in fact not true. Not only did it not have the latest software, it was now ‘End of Life’ (EoL) which means it’s no longer supported by the manufacturer, and there are unlikely to be any more updates, even for security issues. Sometimes manufacturers will issue updates for EoL products if there are many in circulation and the vulnerability is serious. Microsoft released updates for Windows XP well after it was declared as no longer supported.

It’s worth noting that the term ‘end of life’ can very; some use it to describe when the product is no longer supported, whilst others use it to describe the process starting with ‘end of sale’ and ending in ‘end of support’.

This isn’t a complete list, but just a reminder about security vulnerabilities recently raised in broadband routers

  • Netgear WNR614 URL Improper Authentication — Critical vulnerability which can be used remotely which has circulated as a zero-day* since 2024 (CVE-2025-5495). This router is stated as ‘end of service‘ by Netgear although it does appear to affect only older firmware.
  • LinkSys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 (Range Extenders) — Critical vulnerability exploitable remotely. Vendor (part of Cisco) supposedly didn’t respond to the disclosure (CVE-2025-5438). Based on the LinkSys End of Life page the RE6500-UK product is supported until 22/07/2027, five years from the announcement in 2022. It is still being sold on Amazon though with no mention of the two or so years of service life. Other models like the RE6300-UK is supported only until August this year.
  • D-Link DIR-816 — Multiple remote vulnerabilities (CVE-2025-5620 through to 5624 and 5630) relating to a product in End of Life state and no longer supported.

* “Zero-day attacks” are attacks which are out in the wild without a fix from the vendor, typically as it has been found by someone and not reported to the manufacturer responsibly before exploitation.

These issues aren’t just for your broadband router and can affect all home technology (connected appliances, smoke alarms, smart thermostats, alarm systems, connected doorbells, cameras, etc.

If you have a product that is no longer supported, you should be planning to replace it. We’re going to be running features soon on outdated Internet connected (IoT) products and what you need to look out for.

Reply to “More vulnerabilities out there — Have you updated your broadband router’s firmware?”

  1. Internet of Things (IoT) aka Internet of Attack Vector Possibilities.

  2. Yes, as a surprise to me, there was an update for my TP-link router a few weeks ago.

  3. I used to be a TP-Link “fanboy”, everything on the network was from them (switches, router, NiC’s) but now they are quite bad in my view, i spent £300 on what was then a high end router and now just 3 years later its EoL and has only ever had ONE firmware update and that was to update a part of the firmware you have to have a subscription to use anyway.

    Their devices seem to go EoL so fast now im not sure if i will get another TP-Link or not but then the other providers don’t seem any better!

Your name will be published with your comment. You do not need to include your full name when commenting. Your e-mail address will not be published.

Most viewed