Skip to content

Router Vulnerabilities: Governments Call for Security Improvements from Enterprises

To the point: Ten-year-old attack patterns against router vulnerabilities remain highly effective because enterprises fail to replace legacy hardware and treat network security as a secondary concern.

19 authorities from North America, UK, Europe and Australia warn of targeted attacks on router infrastructure by Russian state actors. Through poorly managed network devices and outdated protocols, attackers gain access to sensitive configuration data and critical infrastructure.

As documented by the multinational cybersecurity advisory, attackers consistently exploit insufficiently protected and poorly configured network devices. The approach is established: threat actors deliberately scan for vulnerable routers and compromise them to gain access to critical infrastructure networks. They then transfer configuration files to controlled servers. These files contain login credentials stored in plaintext or with weak encryption, as well as information about the network topology of the affected organisation.

The attack mechanism leverages the Simple Network Management Protocol (SNMP): attackers send requests via SNMP and deliberately search for older SNMPv1 or SNMPv2 devices whose default authentication strings (“Community Strings”) remain unchanged. Using spoofed IP addresses, they instruct the SNMP agents to create configuration files (such as “config.bkp” or “output.txt”) and transmit them to external servers. Additionally, known CVEs are exploited, particularly CVE-2018-0171 and CVE-2008-4128 in Cisco routers as well as vulnerabilities in Cisco’s Smart Install Tool, which enable remote code execution and denial-of-service attacks.

The attacks are attributed to known state actor groups, including “Berserk Bear”, “Crouching Yeti”, “Drouching Yeti”, “Energetic Bear”, “Ghost Blizzard” and “Static Tundra”. Industries particularly at risk include communications, energy, financial services, defence, healthcare and government agencies.

The central problem lies in organisational deficiencies: many enterprises treat routers as requiring no further monitoring after installation and leave their management exclusively to the network team, while security responsibility remains unclear. This is compounded by the use of outdated, no longer supported hardware, whose replacement the business refuses. Router security thus receives significantly less attention than traditional endpoint security.

The participating authorities recommend specifically: immediate switch to SNMPv3, implementation of strong authentication procedures, disabling older protocols and replacement of unsupported devices. Equally important is the explicit assignment of clear security responsibilities and regular review and updating of router configurations as part of routine security hygiene.


Source: www.csoonline.com · Published 14 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: