www.tomsguide.com FCC Bans Foreign-Made Routers Amid Security Concerns
Article Content
- •The FCC banned new foreign-made routers on March 23, 2026, citing national security risks.
- •Only routers with Conditional Approval can receive firmware updates after March 1, 2027.
- •Netgear is currently the only approved manufacturer, while TP-Link faces legal challenges.
On March 23, 2026, the FCC banned new foreign-made consumer-grade routers due to national security risks. This decision affects all router manufacturers without prior FCC authorization, limiting their ability to import and sell new models in the U.S. The ban was prompted by concerns over supply chain vulnerabilities that could be exploited by hackers and foreign adversaries. Currently, only routers with Conditional Approval from the Department of War or Homeland Security can receive firmware updates after March 1, 2027. Netgear has received approval, while TP-Link has not, leading to ongoing legal disputes between the two companies. The ban has significant implications for IT environments, requiring users to verify the origin of their routers. Existing models authorized before the ban can still be sold and used until their firmware support ends.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…