Skip to main content

Morning Overview

The FBI says a router dated 2010 or earlier is probably getting no updates at all

A home router dated 2010 or earlier has probably been orphaned: its manufacturer stopped issuing software updates years ago, and every flaw found since stays open. That is the FBI’s assessment, and the bureau’s Internet Crime Complaint Center put it as a calendar year rather than a vague caution about old equipment. The date gives owners a rule they can check against the label on the underside of the box.

The warning is short but specific. In a public service announcement dated May 7, 2025, the IC3 reported that some end-of-life routers with remote administration switched on had been compromised by a new variant of a malware family called TheMoon. The malware itself is old: it was first discovered on compromised routers in 2014 and has gone through several campaigns since.

The FBI’s 2010 line and what end of life means

The sentence at the centre of the notice, published on the FBI’s IC3 site, reads: “Routers dated 2010 or earlier likely no longer receive software updates issued by the manufacturer and could be compromised by cyber actors exploiting known vulnerabilities.” The same document defines the term. A device is end of life when the manufacturer no longer sells it and is not actively supporting the hardware, which also means no more software updates or security patches.

The word “likely” carries weight. The FBI is describing a pattern across makers, not auditing individual models, so the manufacturer’s own support page remains the final word on any particular router.

A router from 2010 has by now spent more than fifteen years outside any patch cycle, long enough for a long list of published vulnerabilities to accumulate with no fix ever shipped.

TheMoon and the proxy network built from forgotten routers

TheMoon shows what an unpatched router is worth to an attacker. According to the FBI, the malware does not require a password to infect a router; it scans for open ports and sends a command to a vulnerable script. Black Lotus Labs, the threat research team at Lumen Technologies, reported in March 2024 that the botnet had grown to more than 40,000 bots across 88 countries, and that most of them served as infrastructure for a residential proxy service called Faceless. The analysis was carried out by researchers Chris Formosa and Steve Rudd.

A residential proxy rents out the internet address of an ordinary home. Criminals who use one send their traffic through a household connection instead of a data centre, which Lumen described as a way of masking identities and bypassing security controls. The router’s owner supplies the cover without being asked.

Remote administration is the detail that links the two stories. It is a router feature that lets the settings page be reached from the wider internet rather than only from inside the home, and the FBI singled it out as switched on in the compromised devices. An old router with that feature enabled presents an open door on a device that will never receive a repair, and the infection recipe the FBI describes, scanning for open ports and sending a command to a vulnerable script, needs nothing else from the owner.

Replacement, remote administration and the federal precedent

The FBI’s advice is concrete. If the router is at end of life, the bureau says to replace it with an updated model if possible. Any available security patches or firmware updates should be applied immediately. The owner should log in to the router settings, disable remote management and remote administration, save the change and reboot. The bureau also recommends strong, unique passwords of 16 to 64 characters, a measure that matters little against TheMoon but closes other doors.

The federal government applies the same logic to its own networks. As CyberScoop reported, the Cybersecurity and Infrastructure Security Agency issued a binding operational directive on February 5, 2026, giving agencies three months to inventory unsupported edge devices and a year to replace them with supported alternatives. Acting Director Madhu Gottumukkala said unsupported devices pose a serious risk to federal systems, and the directive’s rationale is the same as the FBI’s: devices without patches for new vulnerabilities are a standing route into a network. CISA’s announcement of the order and its guidance on reducing the attack surface of end-of-support edge devices cover the same ground for network owners.

For a home user, the practical check is short. A manufacturing date printed on the label, set against the FBI’s 2010 line, is the quickest first test, and the vendor’s end-of-life list settles the rest.

The FBI’s May 2025 notice names no router brands, so the 2010 date is the only filter it offers. Lumen’s count of more than 40,000 compromised devices in 88 countries, taken from January and February 2024, shows how many unsupported routers had already been captured by one botnet before the bureau published it.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview