Network Security

FCC Bans New Routers Made Outside the US Over National Security Risks

The ban aligns with a White House determination that all routers produced abroad are a threat to national security.

FCC

The Federal Communications Commission (FCC) this week added all consumer-grade routers produced in foreign countries to its Covered List, banning their use in the US.

The decision was based on a White House-convened Executive Branch interagency body’s determination (PDF) that all routers made abroad pose a threat to national security.

“Compromised routers can enable in-depth network surveillance, data exfiltration, botnet attacks, and unauthorized access to US government or American businesses’ networks. The United States must have secure and trusted routers,” the determination reads.

According to the document, because most of the routers used in American homes today are produced outside of the US, this market domination “creates unacceptable economic, national security, and cybersecurity risks.”

The determination also mentions attacks by state-sponsored groups such as Flax Typhoon, Salt Typhoon, and Volt Typhoon, which targeted critical communications, energy, transportation, and water infrastructure in the US.

“Routers in the United States must have trusted supply chains so we are not providing foreign actors with potential built-in backdoors to American homes, businesses, critical infrastructure, and emergency services,” the assessment reads.

Advertisement. Scroll to continue reading.

Based on this determination and on President Trump’s 2025 National Security Strategy, the FCC updated its Covered List with all routers made abroad, pointing out that devices that are currently in use within Americans’ houses are not impacted.

“New devices on the Covered List, such as foreign-made consumer-grade routers, are prohibited from receiving FCC authorization and are therefore prohibited from being imported for use or sale in the U.S. This update to the Covered List does not prohibit the import, sale, or use of any existing device models the FCC previously authorized,” the FCC announced (PDF).

Furthermore, certain router models may be exempt from the ban if they are specifically approved by the Department of War (DoW) or the Department of Homeland Security (DHS).

Per the determination, the DoW or the DHS should notify the FCC that the respective router models have received Conditional Approval (PDF) and do not pose unacceptable risks to national security, and they will continue to receive FCC equipment authorizations.

Supply chain vulnerabilities that could disrupt the US critical infrastructure, economy, and national defense, and severe cybersecurity risks leading to critical infrastructure disruptions or direct harm to US persons are considered unacceptable threats.

Related: DoE Publishes 5-Year Energy Security Plan

Related: Poland Faced a Surge in Cyberattacks in 2025, Including a Major Assault on the Energy Sector

Related: Iran Built a Vast Camera Network to Control Dissent. Israel Turned It Into a Targeting Tool

Related: 3 Men Charged With Conspiring to Smuggle US Artificial Intelligence to China

Related Content

Network Security

Forescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem.

Government

Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks.

Vulnerabilities

Tracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device's web management interface.

Malware & Threats

The exploitation of the command injection vulnerability started one year after public disclosure and PoC exploit code publication.

Vulnerabilities

In-the-wild exploitation has been ongoing for a year, but no successful payload execution has been observed.

Vulnerabilities

The security defects could be used to bypass authentication, execute arbitrary commands, and decrypt configuration files.

Vulnerabilities

An out-of-band security update for Junos OS Evolved patches the remote code execution vulnerability CVE-2026-21902.

Vulnerabilities

The issue impacts the UPnP function of multiple device models and could be exploited for remote code execution.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version