The Federal Communications Commission banned new consumer internet routers manufactured outside the United States in March, citing national security concerns. The ban does not affect routers already in American homes or those currently on sale in the US, but all new routers aimed at the consumer market now require approval. Manufacturers can apply for exemptions, and some have already been approved, including Asus, which received Conditional Approval in September 2026.

The FCC wrote that malicious actors have exploited security gaps in foreign-made routers to attack American households, disrupt networks, enable espionage, and facilitate intellectual property theft. The agency also stated that foreign-made routers were involved in the Volt, Flax, and Salt Typhoon cyberattacks targeting vital US infrastructure. Foreign-made consumer routers were added to the Covered List, which details equipment and services deemed to pose an unacceptable risk to US national security.

Bogdan Botezatu, director of Threat Research at cybersecurity firm Bitdefender, said the ban is a step to harden the cybersecurity readiness of US households given ongoing geopolitical tensions. He said consumer routers sit at the edge of every home network, making them an attractive target and a strategic risk if compromised at scale. Asked whether the risk is real, Botezatu said yes, though there is no easy way to prove intent, adding that Internet of Things devices, including routers, are a weak point across the internet.

The ban only affects the sale of new Wi-Fi routers and mobile Wi-Fi or hotspot devices aimed at consumer households. It does not apply to existing FCC-approved routers on sale in the US or to phones with hotspot features, and previously purchased routers already in use are also fine, according to the FCC's FAQ. These routers can continue to be sold, used, and updated with new firmware at least until January 1, 2029.

Any new router manufactured outside the US now requires FCC approval before it can be imported, marketed, or sold in the US. This includes routers from US companies manufactured overseas, which is the vast majority of the market right now. The ban is concerned with consumer-grade routers and could include any designed or manufactured outside the US or manufactured by companies that are not completely US-owned and operated. All the major players in the market, including Netgear, TP-Link, Asus, Amazon's Eero, Google's Nest, Synology, Linksys, and Ubiquiti, fall under the definition, as do most, if not all, of the routers supplied by internet service providers in the US.

Manufacturers can apply for Conditional Approval from the Department of Defense and the Department of Homeland Security. Companies that receive Conditional Approval can continue to sell and update existing devices and release new routers, mesh systems, and mobile hot spots for 18 months, including firmware and other software updates, while all new devices are subject to the regular FCC approval process. Other companies granted Conditional Approvals so far include Zyxel, Gryphon, SpaceX, Adtran, Calix, Nokia, and Sagemcom.

The Consumer Technology Association has appealed via an FCC filing for greater clarity and clearer guidelines, also raising concerns about software patching and component updates. The FCC initially published a waiver covering software and firmware updates until March 1, 2027, and has now extended that waiver at least until January 1, 2029. Matt Wyckhouse, Founder and CEO of Finite State, said the biggest practical security risk with routers is not only who made them but whether they remain patched, and that the original restriction risked leaving millions of deployed routers unable to receive security fixes. The majority of routers compromised and used in cyberattacks are older end-of-life devices that no longer receive security updates.

More gadget news from TechManNews.