FCC bans foreign routers amid supply chain, cyber risks.
Mar 25, 2026 // 10:55 - Norina Velotta


The FCC announced Monday it’s prohibiting the import of certain new, foreign-made home internet routers due to “unacceptable” cybersecurity and national security threats.

FCC Chair Brendan Carr stated on X that the decision aims to protect Americans and the vital communications infrastructure. Consequently, new foreign-manufactured router models will no longer be permitted for sale or marketing in the U.S. This action follows a national security assessment from Executive Branch Agencies, according to Carr.

As a result, all consumer routers made abroad are now on the Covered List, unless the Department of War (DoW) or the Department of Homeland Security (DHS) grants them Conditional Approval after determining they pose no risks.

Currently, the approved list includes only drone systems and software-defined radios (SDRs) from SiFly Aviation, Mobilicom, ScoutDI, and Verge Aero. Foreign router manufacturers may apply for Conditional Approval. BBC News reports that Starlink routers are exempt as they are made in Texas, USA.

The FCC explained that the Executive Branch’s decision was based on concerns that foreign-made routers (1) present “a supply chain vulnerability that could disrupt the U.S. economy, critical infrastructure, and national defense” and (2) create “a severe cybersecurity risk that could be leveraged to immediately and severely disrupt U.S. critical infrastructure and directly harm U.S. persons.”

The agency said that both state-sponsored and independent cybercriminals are exploiting vulnerabilities in routers used in homes and small offices to infiltrate American residences, disrupt networks, conduct cyber espionage, and steal intellectual property. Furthermore, these devices might be integrated into large networks to facilitate password guessing attacks, unauthorized network access, and espionage proxies.

It’s been observed that China-linked groups like Volt Typhoon, Flax Typhoon, and Salt Typhoon are using botnets consisting of foreign-made routers to launch attacks on U.S. communications, energy, transportation, and water systems.

According to the National Security Determination (NSD), “In Salt Typhoon attacks, state-backed hackers utilized compromised foreign routers to gain persistent access to networks and move to other targets.”

The U.S. government also pointed to a botnet known as CovertNetwork-1658 (also called Quad7), which has been employed in highly sophisticated password spraying attacks. This activity is believed to be carried out by a Chinese cyber actor known as Storm-0940.

It’s important to note that this update to the Covered List doesn’t affect routers already in use by consumers and retailers can continue selling previously FCC-approved devices.

The NSD warned, “Insecure, foreign-produced routers are attractive targets for attackers used in recent cyberattacks for network access and as attack platforms against critical infrastructure. The vulnerabilities introduced into American networks and critical infrastructure by foreign-made routers are unacceptable.”

Routers are a major target for cyberattacks as they are the gateway to internet access. A compromised router allows hackers to monitor network traffic, steal data, and deploy malware. In his 2014 book No Place to Hide, journalist Glenn Greenwald claimed the NSA routinely intercepts routers before export by US manufacturers to inject backdoors.

#amid  #bans  #chain  #cyber  #fcc  #foreign  #news  #risks,  #routers  #supply   —   News