Quick fix (4 steps)
- Find your router address (default gateway), open it in a browser and sign in.
- Open the firmware page (ASUS: Administration, Firmware Upgrade; MikroTik: System, Packages) and install the newest version for your exact model.
- Turn off remote administration, SSH or WinBox from the internet, UPnP and any VPN server you do not use.
- Check the DNS fields and the user list for anything you did not set. If you find something, go to the reset checklist.
What happened: ASUS and MikroTik router warnings, and what is confirmed
In the last week of September 2026, two separate router stories spread worldwide: a reported critical flaw in ASUS routers triggered by malicious VPN configuration files, and a remote code execution problem in MikroTik RouterOS. The safe response is the same for both: confirm your model, install the newest firmware from the vendor, and close every management door you do not use. This article separates what we could confirm on primary pages from what is only press coverage, so you know exactly how much weight to give each claim.
Here is what we actually opened on October 1, 2026. On MikroTik's own security advisories page, a critical RouterOS vulnerability dated September 3, 2026 is described as "MikroTrick", with the related identifiers CVE-2026-67276, CVE-2026-86060 and CVE-2026-67277. MikroTik lists it as fixed in RouterOS 7.25 beta 3, 7.24.2, 7.23.4 and 6.49.21, and its key recommendation is to make sure SSH is not open to untrusted networks and to inspect the configuration for unknown scripts or users after upgrading. A second entry dated September 16, 2026 (CVE-2026-52346) covers a TLS inspection issue that can crash the router or leak a small amount of memory, fixed in 7.22.2 (stable) and 7.21.4 (long-term).
On CISA's Known Exploited Vulnerabilities catalog we found CVE-2026-67279, named "Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability", added on September 25, 2026. The catalog text says it lets an unauthenticated client open a session channel and send an exec request, and that it can be exploited when chained with another CVE. We did not find an ASUS router entry among the September and October entries shown on that page.
For ASUS, we must be honest: the ASUS security advisory page we could open did not display advisory content, so we could not read a CVE number, a list of affected models or a fixed firmware version from ASUS. The story about a critical flaw triggered by malicious VPN files comes from security news coverage published around October 1. For ASUS owners the practical rule is therefore simple: open the support page for your exact model, install the latest firmware, and do not import VPN configuration files from sources you do not fully trust.
What we could not confirm
We did not read an ASUS advisory, so this guide does not name ASUS CVE IDs, affected models or fixed firmware numbers. Check the vendor advisory for your model. We also do not state that any specific attack is happening against your router: the only exploitation signal we read is the CISA catalog entry for MikroTik.
The short version: who needs to act today
If your router is an ASUS, a MikroTik, or any brand that has not had a firmware update in the past 12 months, you should act this week. Checking takes ten minutes, and updating usually takes another fifteen. Most home users never log in to their router after the day it was installed, which is exactly why router flaws are valuable to attackers: the device sits at the edge of the network, runs all the time, and nobody is watching it.
| Your situation | What to do first | Urgency |
|---|---|---|
| ASUS router at home, auto-update never configured | Log in, check firmware, install the latest for your model, turn off remote access you do not use | This week |
| MikroTik router (hAP, RB, CCR, CRS series) at home or office | Check the RouterOS version against the fixed versions above, upgrade, close SSH and WinBox to the internet | Today |
| ISP-supplied box (Bell, Videotron, Rogers, Telus, Cogeco) | It is usually updated by the provider; check that remote management is off, and ask them if unsure | This month |
| TP-Link, Netgear, Linksys, Eero, Google Nest Wifi | Confirm the latest firmware is installed and turn on automatic updates | This month |
| Router older than 6 to 7 years, no updates offered | Plan a replacement; see the buy-or-replace section | Within a few weeks |
| Small office with a VPN server on the router | Patch first, then review who has VPN access and rotate credentials | Today |
If you only have five minutes, read the quick fix at the top, then go to the section for your brand. If you suspect the router has already been tampered with, jump to the signs of compromise and the reset checklist below. For general background on what a healthy home network looks like, our home Wi-Fi router security guide covers the fundamentals, and this article builds on it with brand-specific steps for this week's alerts.
Why routers are such attractive targets
A router is a small computer that every other device trusts. If an attacker controls it, they can watch or redirect traffic, reach devices that were never meant to face the internet, and use your connection to attack other people, all without touching your laptop. That is why vendors and agencies keep issuing router warnings, and why those warnings matter even when you personally feel you have nothing worth stealing.
There are four reasons routers are hit so often. First, they are always on and always reachable from the internet in some way, whether through a web admin page, a VPN server, a remote-management feature or a forgotten port forward. Second, they run stripped-down software that is rarely patched by the owner. Third, they have no antivirus and no obvious alerts, so a compromise can last for years. Fourth, one router often protects dozens of devices: phones, TVs, cameras, laptops, a work-from-home PC, and a printer.
What can an attacker do with a compromised router? The typical outcomes are changing the DNS settings so that bank and email addresses resolve to look-alike sites, injecting redirects or ads, harvesting unencrypted traffic, opening access to the internal network, adding the router to a botnet that sends spam or attacks, and using the connection as an anonymising relay so that illegal activity appears to come from your address. For a business, any of these can become a privacy incident, and in Quebec that can trigger obligations under Law 25.
The positive side is that router hygiene is among the cheapest security work you can do. The big levers are few: current firmware, a strong unique admin password, remote administration off, unused services off, and a clean Wi-Fi password. We walk through each, brand by brand, in the sections below. Our companion article on signs a router or smart home device is hacked goes deeper into symptoms, and here we add the specific checks to run after this week's alerts.
One more point about timing. When a flaw is publicly described, the window between disclosure and widespread scanning is often short. Even if no one is targeting you personally, automated tools sweep the internet for vulnerable devices. That is why we recommend patching within days, not months, when the vendor has already released a fix. If the vendor has not yet published a fixed version for your exact model, the interim step is to reduce exposure: turn off remote administration, turn off features you do not use, and watch the vendor page for the update.
Before you touch anything: what to prepare in ten minutes
Write down your router brand and exact model, your current firmware version, and the admin login, and save a copy of your configuration before updating. A firmware update almost always works, but a five-minute backup makes any problem easy to undo. Do the update from a computer connected by Ethernet cable if you can, because Wi-Fi drops briefly during a restart and a cable removes any doubt.
Preparation checklist
- I found the model name and hardware version on the label under the router.
- I know the admin username and password (not the Wi-Fi password). If the label still shows the factory default, I will change it today.
- I noted my internet settings if I use PPPoE, static IP, VLANs or a special ISP setup, in case I need to re-enter them.
- I exported or screenshot the main settings: Wi-Fi names, port forwards, DHCP reservations, DNS.
- I picked a calm moment: no video calls, no one working remotely for the next 20 minutes.
- For a business: I told staff the internet will drop for a few minutes.
- I have a phone with mobile data in case I need to download firmware while the router restarts.
Where do you find the model? It is printed on a sticker, usually under or behind the unit, and looks like a short code (for example a series name followed by letters and digits). Hardware version matters: some brands publish different firmware for revision A and revision B of the same product name. Installing firmware for the wrong revision is the single most common way to turn an update into a problem, so check twice.
Also decide now whether you will use automatic updates. Several current routers can check for firmware on a schedule and install it overnight. For a home that is the right default. For an office where an unplanned restart would hurt, choose a weekly maintenance window instead and put it in the calendar.
Finally, do not download firmware from search results, forums or file-sharing sites. Use only the vendor's official support page for your exact model, or the router's own built-in update button. Fake "firmware" files are a known trick, and an unofficial image can contain malware that survives a normal reset.
How to check your router firmware version (any brand)
Open the router's admin page in a browser, sign in, and look for a page named Firmware, System, Administration or Maintenance. The version number shown there is what you compare against the vendor's latest release for your exact model. If you cannot find the admin page, the address is almost always your default gateway, which Windows and macOS can show you in a few clicks.
- Find the router address. On Windows, press Windows + R, type
cmd, then runipconfigand read the "Default Gateway" line. On a Mac, open System Settings, Network, your connection, Details, TCP/IP, and read "Router". On an iPhone, Settings, Wi-Fi, the "i" next to your network, "Router". Typical values are 192.168.0.1, 192.168.1.1, 192.168.50.1 or 10.0.0.1. - Type that address into a browser on a device connected to the network and sign in with the admin account. If you never set one, the factory login is printed on the label; change it right away.
- Locate the firmware page. Look for Firmware Upgrade, Software Update, Router Update or System Tools. Write down the version string exactly as shown.
- Compare with the vendor. On the vendor's support site, open the download page for your exact model and hardware revision and read the latest firmware version and its release notes. If the notes mention security fixes, update now.
- Install, then re-check. Use the router's built-in update button when it works. If it says you are up to date but the vendor page shows a newer file, download the file from the vendor and upload it manually.
If the router never offers a new version and the vendor page shows no download newer than three or four years, that is a sign the model is end of life. Do not panic, but read the buy-or-replace section later in this guide, because an unsupported router cannot receive fixes for newly discovered flaws.
Many people use the mobile app (ASUS Router app, TP-Link Tether or Deco, Netgear Nighthawk, Linksys, Eero, Google Home). Apps are convenient and often show a banner when firmware is available. They are a fine way to update, but an app can lag behind, so for an alert week we still recommend confirming on the vendor page that you are on the current version.
ASUS routers: update ASUSWRT firmware step by step
On an ASUS router, sign in at router.asus.com or the gateway address, open Administration, then Firmware Upgrade, run the check, and install the newest version for your model. Then turn off the features you do not use, especially remote access from the internet and the VPN server if you do not run one. ASUS has not been confirmed by us as having a specific fixed version for this week's reported flaw, so install whatever is newest on the support page for your model.
Press coverage on October 1 described a critical ASUS flaw that can be triggered by malicious VPN files. We could not read the vendor's own advisory, so we cannot tell you which models or which firmware numbers are involved. What you can do safely is the following sequence.
- On a computer connected to the router, open
http://router.asus.com(or the gateway address, often 192.168.50.1 or 192.168.1.1) and sign in. - Open Administration in the left menu, then the Firmware Upgrade tab. Note the version under "Firmware Version".
- Click Check. If a new version is found, click Upload or follow the on-screen prompt. Do not unplug the router during the update, which can take several minutes. The page will reload by itself.
- If the router says nothing new is available, open ASUS's support site, search your exact model, open Driver and Utility, then BIOS and Firmware, and compare the date and version. If a newer file exists, download it, unzip it and use "Manual firmware update" to select the file.
- After the restart, return to the same page and confirm the new version number.
- Open the Administration, System tab. Make sure "Enable Web Access from WAN" is set to No, and that SSH and Telnet are disabled unless you truly use them. If you must use remote access, restrict it to a specific IP and use a non-default port.
- Open VPN. If you do not use the router's VPN server, leave it off. If you use the VPN client feature, do not import configuration files that came from an email, a forum or a stranger. A VPN file is code-like configuration, and it deserves the same caution as running an unknown program.
- Open WAN, Internet Connection and turn UPnP off unless a specific device needs it (see the UPnP section below). Also turn off AiCloud or remote file access if you do not use it.
- Change the admin password to a long, unique one, and change the admin username if the model allows it.
Menu names vary a little between ASUSWRT versions and between newer and older models, so if you do not see an exact item, search the page for the keyword or use the search box in the top bar of the interface. ASUS also offers an automatic update option on many models: look for "Auto firmware upgrade" or similar and set it to a time when no one is online, for example 3 a.m.
If you use Asuswrt-Merlin
Merlin is a community firmware built on the ASUS code, with its own release schedule and its own announcements. Updates are installed from the same Firmware Upgrade page, with the Merlin build for your model, and Merlin's release notes usually say which ASUS code changes were merged. Merlin may lag or lead the stock firmware for a given flaw, so check the Merlin project's own release page for your model rather than assuming it behaves like the stock version.
Some ASUS models are paired in an AiMesh network. In that case update the main router first, then the mesh nodes, which the AiMesh page lets you do from the same interface. Updating nodes separately and out of order can leave the system briefly unstable, so give each step a few minutes.
What if your ASUS model has no new firmware?
If your model shows a last firmware date that is several years old, it may be at the end of its support. In that case, the safest steps are to turn off every remote feature, use a strong admin password, and plan a replacement. Our section on buying or replacing a router lists what to look for in a new one. You can also use our guide on whether Wi-Fi 6E or Wi-Fi 7 is worth upgrading to in 2026 to choose with both speed and security support in mind.
A word on VPN configuration files
Why would a VPN file be dangerous? A VPN profile such as an OpenVPN .ovpn file can contain many instructions, not just a server address and certificate. A router that does not validate those fields properly may process something an attacker planted. For a home user the rule is easy: only import a VPN configuration that you created yourself or that came directly from your VPN provider's official site over HTTPS. For a business, keep a short written list of approved VPN profiles and who may install them.
| ASUS item to check | Where (typical) | Safe setting |
|---|---|---|
| Firmware version | Administration, Firmware Upgrade | Newest for your exact model |
| Web access from WAN | Administration, System | No |
| SSH / Telnet | Administration, System | Off (SSH only on LAN if needed) |
| VPN server | VPN | Off unless you use it |
| Imported VPN profiles | VPN client | Only your own or provider-official |
| UPnP | WAN, Internet Connection | Off unless required |
| AiCloud / remote file access | AiCloud | Off unless required |
| Admin password | Administration, System | Long and unique |
After you finish, scroll to the System Log page and look for unfamiliar sign-ins or restarts around the date of the news. A clean log is reassuring, though not proof, because a skilled intruder can clear it. The signs-of-compromise section below shows stronger checks.

MikroTik RouterOS: check the version and upgrade
For MikroTik, the vendor's own advisory page lists RouterOS 7.24.2, 7.23.4 and 6.49.21 (and 7.25 beta 3) as fixed releases for the critical September 2026 issue, and tells owners to make sure SSH is not open to untrusted networks. Upgrade to the newest release in your channel, then restrict who can reach the management services. MikroTik gear is common in small offices, wireless ISPs, warehouses and home labs, and it is powerful, so its default exposure depends heavily on how it was configured.
Here is what we read on the MikroTik security page on October 1, 2026, and how to use it. The September 3 entry, described as a critical RouterOS vulnerability named "MikroTrick" with CVE-2026-67276, CVE-2026-86060 and CVE-2026-67277, lists these fixed versions: 7.25 beta 3, 7.24.2, 7.23.4 and 6.49.21. The page also states that if you upgrade, you should inspect the configuration for unknown scripts or users. The September 16 entry (CVE-2026-52346) affects routers with at least one firewall rule matching TLS connections through the tls-host feature, and is fixed in 7.22.2 (stable) and 7.21.4 (long-term). Separately, CISA lists CVE-2026-67279 in its Known Exploited Vulnerabilities catalog as of September 25, 2026, with the description that an unauthenticated client can open a session channel and send an exec request, and that exploitation can chain with another CVE.
We have not read a statement tying CVE-2026-67279 to a specific fixed RouterOS version, so do not assume. The practical answer is to move to the newest version available in your channel and to read the changelog for that version. If your router runs RouterOS v6, the only fixed v6 version named on the advisory page is 6.49.21, so check that you reach at least that, and consider planning a move to v7.
Step 1: check the current version
- Open WinBox (Windows, and runs on macOS and Linux through Wine or the native build) or the web interface (webfig) by typing the router's IP in a browser.
- Go to System, Resources. The field "Version" shows your RouterOS release, and "Board Name" shows your hardware.
- Open System, Packages to see the installed packages and their versions. Check that the version is equal to or newer than the fixed releases above for your branch.
- You can also use a terminal:
/system resource printshows version, architecture and board name.
Step 2: back up, then upgrade
- Back up first. Go to Files and create a binary backup with
/system backup save name=pre-upgrade, and an export with/export file=pre-upgrade-export. Download both files to your computer. Treat the export as sensitive, since it can contain secrets in some versions. - Open System, Packages and choose Check For Updates. Pick the channel: "stable" or "long-term". For a business router, the long-term channel changes less often; for a home router the stable channel is fine. Avoid "testing" and beta releases on production routers.
- Read the changelog shown for the target version. If there is a large jump (for example from 6.x to 7.x), read the upgrade notes first: RouterOS v7 changes some features, and a jump across major versions deserves a test.
- Click Download&Install. The router downloads the package and restarts. This takes a few minutes.
- After the restart, open System, RouterBOARD and, if the "Current Firmware" is older than the "Upgrade Firmware", click Upgrade and reboot once more. This updates the bootloader firmware and is separate from RouterOS itself.
- Confirm the new version in System, Resources.
If you manage a router remotely with no one on site, prefer to schedule the change outside of working hours and have a plan to reach the device if the update fails. A safe-mode toggle in WinBox protects against locking yourself out when you change firewall rules, but it does not apply to firmware updates, so keep a console or out-of-band option in mind for critical locations.
Step 3: restrict management access
The MikroTik advisory's main recommendation, that SSH must not be open to untrusted networks, is the central idea of router hardening. Management services should only be reachable from your internal management network or from a specific trusted address, never from "anywhere".
- Open IP, Services. You will see the list of services, such as api, api-ssl, ftp, ssh, telnet, winbox, www and www-ssl.
- Disable what you do not use. Telnet and FTP are rarely needed. The API services can be disabled if no application uses them. The unencrypted www service can be off if you use www-ssl.
- Restrict the rest. For SSH, WinBox and www-ssl, set the "Available From" field to your management subnet (for example, a single admin PC address or your LAN) so that the internet cannot reach them.
- Check IP, Firewall, Filter Rules: make sure the input chain drops traffic to the router from the WAN interface except for the few things you need (established and related connections, ICMP if you want it, and your VPN). A common approach is to add an accept rule for the management addresses and a drop rule for everything else coming from the WAN.
- Check IP, Neighbor Discovery and Tools, MAC Server settings. Limit MAC-Telnet and MAC-WinBox to the internal interface list only.
- Review System, Users. Remove accounts you do not recognize and give each admin a named account with a strong password. Disable the default "admin" account if you have another full-rights account.
- Review System, Scripts and System, Scheduler. Unknown scripts or scheduled tasks are a red flag, and MikroTik specifically recommends looking for them after an upgrade.
- Review IP, DNS and make sure "Allow Remote Requests" is off unless this router is meant to be a DNS server for your network, and then limit it with the firewall.
Do not lock yourself out
Before restricting services, confirm that you can reach the router from the address you will allow. Turn on Safe Mode in WinBox (the Safe Mode button) while you change firewall rules: if the connection drops, the router reverts the changes automatically. Keep a second admin PC or console cable available for critical sites.
Step 4: look for signs of an existing compromise
Upgrading closes the hole for future attempts, but it does not remove something that was installed earlier. After upgrading, do these checks. List users with /user print and compare with who should exist. Check /system script print and /system scheduler print. Check /ip service print, /ip proxy print, /ip socks print and /ip dns print for settings you did not choose. Look at /ip firewall nat print for redirect rules you did not add. Check /interface list and the VPN sections (/interface wireguard, /ppp secret, /interface ovpn-server) for peers or accounts you do not recognize. Review /log print for logins from addresses that are not yours.
If anything unexpected appears, change every password that the router knows (admin, VPN users, Wi-Fi pre-shared keys, any API credentials stored on connected systems), and consider the reset-and-reconfigure path described later, because a router with unknown scripts or accounts may be hard to trust after cleaning by hand. Remember that a factory reset followed by importing an old export can bring the malicious entries back, so rebuild the settings by hand or from a configuration you know to be clean.
| RouterOS item | Where | Safe state |
|---|---|---|
| Version | System, Resources | At or above the vendor's fixed release for your branch |
| RouterBOARD firmware | System, RouterBOARD | Current equals upgrade |
| SSH / WinBox / www-ssl | IP, Services | Limited to the management addresses |
| Telnet / FTP / API | IP, Services | Disabled unless needed |
| Users | System, Users | Only known, named accounts |
| Scripts and scheduler | System | Only entries you created |
| Firewall input chain | IP, Firewall | Drop from WAN except what you need |
| DNS remote requests | IP, DNS | Off unless intended |
Some MikroTik routers are managed by a service provider or by a managed IT partner. If that is your case, do not change settings on your own; ask the provider to confirm that your device is on a fixed version. If you are not sure who manages it, the simplest approach is to log in and check the version yourself, then ask the person who installed it to take over the next steps.
TP-Link, Netgear, Linksys, Eero and Google Nest Wifi: the basics
On every consumer router brand the routine is the same: sign in or open the app, find the firmware or software update page, install the newest version, and turn on automatic updates if the model supports it. The menu names differ, the logic does not. None of these brands is named in the two alerts we cover, so this section is about good hygiene rather than a specific flaw, and you should still check each vendor's advisory page for your model.
| Brand | Where to update | Auto-update | Tip |
|---|---|---|---|
| TP-Link (Archer, Deco) | Web: Advanced, System, Firmware Upgrade or Online Upgrade. App: Tether or Deco, More, Firmware | Available on many models (Auto Update under System) | Check hardware version (V1, V2) before manual download |
| Netgear (Nighthawk, Orbi) | Web: Advanced, Administration, Firmware Update (or Router Update). App: Nighthawk or Orbi | Many models offer auto-check | Orbi: update the main router first, satellites follow |
| Linksys (Velop, others) | Web: Connectivity, Router Firmware Update. App: Linksys app | Automatic updates by default on many recent models | Confirm "Automatic" is set, not "Manual" |
| Eero | App only: Settings, Advanced, check the current software | Automatic by design | Check the app for pending updates and restart |
| Google Nest Wifi / Google Wifi | Google Home app, Wi-Fi, Settings | Automatic by design | Confirm the network shows as up to date |
| ISP gateway (Bell, Videotron, Rogers, Telus, Cogeco) | Managed by the provider | Provider pushes updates | Do not install third-party firmware; ask provider about remote management |
The above menu paths reflect common layouts and can differ by model or year, so use them as a guide and use the search function of the interface if a menu is missing. For exact download files, always go to the vendor's official support page and search by model number and hardware version.
TP-Link in more detail
Sign in at tplinkwifi.net or the gateway address, open Advanced, then System, then Firmware Upgrade. Choose Online Upgrade if available, or download the .bin file for your exact version and use Local Upgrade. Afterwards, look under Advanced, Security for remote management options and turn off "Remote Management" or "Web Management from WAN" unless you truly need them. Deco mesh users update from the Deco app, which handles the main unit and satellites together.
Netgear and Orbi in more detail
Sign in at routerlogin.net, then open Advanced, Administration, Firmware Update. Netgear's page offers "Check" and "Manual Update". After updating, open Advanced, Advanced Setup, Remote Management and make sure it is off. If your router offers a cloud account (Netgear Armor, Nighthawk app), review which devices can manage it. Orbi systems update satellites after the main unit; wait for the status light to settle before testing.
Linksys, Eero and Google Nest Wifi
Linksys Velop and Eero are designed around the app, and automatic updates are usually on. Your job is just to make sure they actually run: open the app, find the version, and verify there is no pending update or a device that has been offline for weeks. Google Nest Wifi receives updates automatically from Google, and the Google Home app shows whether the network is up to date. For all three, enable two-step verification on the account that manages the router, since that account is now a key to your network. Our two-factor authentication setup guide shows how.
Provider-supplied gateways
If your router belongs to your internet provider, you often cannot flash firmware yourself, and you should not try. What you can do is sign in to its admin page and check three things: remote management is off, the Wi-Fi password is not the factory default if you can change it, and the guest network is separate. If the provider's device is old or has features that you cannot control, call the provider and ask directly whether it has the latest firmware and whether remote management is enabled by default. Some owners add their own firewall router behind the provider's modem and keep the provider box in bridge mode, which gives full control over updates.
Turn off remote administration, UPnP and VPN features you do not use
The fastest way to shrink your router's attack surface is to turn off every service reachable from the internet that you do not actively use: remote administration, UPnP, the built-in VPN server, FTP or media sharing, and cloud-access features. Every disabled feature is a door that stays shut even before the next flaw is announced. This is also the best protection while you wait for a vendor to publish a fixed firmware.
| Feature | What it does | Risk when exposed | Recommendation |
|---|---|---|---|
| Remote administration (web access from WAN) | Lets you open the admin page from outside | Exposes the login page to the entire internet | Off. If you must, use a VPN into your network instead |
| SSH / Telnet / WinBox from WAN | Command-line or admin tool access from outside | Brute force and flaw exploitation | Off, or restricted to specific addresses |
| UPnP | Lets devices open ports automatically | Malware or misbehaving apps can open holes | Off unless a game or app needs it, and then review the open-port list |
| VPN server (OpenVPN, WireGuard, PPTP) | Lets you connect into home from abroad | An unpatched or weak VPN service is an entry point; PPTP is outdated | Off if unused; patched, strong keys if used |
| VPN import of unknown profiles | Adds an outgoing VPN | Untrusted profiles can carry harmful settings | Import only from your own or the provider's official source |
| Cloud / remote file access (for example router-attached USB drive) | Reach files from outside | Exposes personal files | Off unless needed; use a strong password |
| WPS | Easy device pairing by PIN or button | PIN mode can be attacked | Off |
| DMZ host / broad port forwards | Sends internet traffic to one device | That device becomes directly exposed | Remove unless essential |
| Guest network | Separate Wi-Fi for visitors | None if isolated | On, with client isolation |
How to see what your router exposes to the internet
From the router admin page, review the "Port forwarding", "Virtual server", "NAT" and "UPnP" tables. Any entry you do not recognize is worth investigating. To see how your home address looks from outside, you can use an external port scanner from a reputable security site while connected to your home network, and look at open ports. Avoid unknown "free scan" sites asking for downloads. Typical open ports to be concerned about include 22 (SSH), 23 (Telnet), 80 and 443 (admin pages), 8291 (a common MikroTik management port), 8080 and 8443 (alternate admin ports). A port can be open for a good reason, for example a camera or a game server, but every open port should have a purpose you can name.
Router exposure checklist (print or screenshot)
- Remote administration from the internet: OFF.
- SSH and Telnet: OFF, or limited to my own address.
- UPnP: OFF, or I reviewed the open-port list.
- VPN server: OFF, or patched, with a strong key and named users.
- I did not import a VPN file from an email, a forum or a stranger.
- WPS: OFF.
- Port forwards and DMZ: only entries I can explain.
- Guest network: ON and isolated from my main devices.
- Admin password: long, unique, not on a sticky note stuck to the router.
- Automatic firmware updates: ON (or a calendar reminder every month).
- Router admin account (cloud login): two-step verification enabled.
If you need to work from outside, a better pattern than leaving the admin page open is to use a VPN service that you keep patched, or a cloud-managed option from the vendor with a strong account protection. When in doubt, close the door and ask a professional to set up secure remote access for you. Our guide on antivirus versus VPN explains what a VPN does and does not protect, which is useful before you decide to run one at home.
Finally, set the DNS. Many routers let you choose the upstream DNS servers. Using your provider's defaults is fine. Using a well-known public resolver is also fine. What matters is that you know what is configured, because an unexpected DNS address is among the most common marks of a tampered router, as we discuss in the next section.
Signs your router may be compromised
The most reliable signs of a tampered router are DNS servers you did not set, admin accounts or scripts you did not create, unexpected port forwards or VPN peers, and browser redirects that happen on every device at home. One sign alone can be a glitch; two or more together deserve a full reset. There is no single test that proves a router is clean, so combine several checks.
| Sign | How to check | What it can mean |
|---|---|---|
| DNS servers changed | Router admin page, WAN or Internet settings, DNS fields; compare with your provider's or your own choice | Traffic is sent to a resolver controlled by someone else |
| Redirects or odd pop-ups on all devices | Try a phone on mobile data versus the same site on home Wi-Fi | Network-level redirect, not a single infected PC |
| Certificate warnings on well-known sites | Browser shows a warning for your bank or email only at home | Possible interception; stop and do not click through |
| Unknown admin accounts or changed login | Router users or administration page | Persistence by an attacker |
| Unknown port forwards, DMZ, UPnP entries | NAT or port-forward tables | Hidden access to an internal device |
| Unknown VPN peers, scripts, scheduled tasks | VPN pages, scripts and scheduler (RouterOS) or startup scripts (Merlin, if you use them) | Backdoor or botnet agent |
| Remote management turned on that you did not enable | Administration or services page | Someone opened the door for later |
| Router slow, hot, rebooting, or LEDs blinking with no one online | Check connected-device list and traffic stats | Heavy outbound traffic such as spam or attack traffic |
| Provider warns about abuse or blocks your line | Email or call from the provider | Your address was used in an attack |
| Firmware version changed or settings reset without you | Compare with your notes | Tampering or a power-related reset; investigate |
A quick DNS check anyone can do
Open the router's WAN or Internet page and read the DNS fields. If they are blank or "automatic", your router uses the provider's DNS, which is normal. If they show addresses, search for each one and confirm it belongs to a resolver you recognise (your provider, or a public service you chose). On a computer, the commands nslookup example.com (Windows) or scutil --dns (Mac) show which DNS server a device actually uses. If a device uses an address that is not your router or a resolver you configured, investigate. Also compare with a phone on mobile data: if a bank site shows a warning only on your home network, treat that as a serious sign.
Things that look scary but are usually not a compromise
A slow connection after an update, a router reboot after a power cut, a Wi-Fi name change caused by a mesh firmware update, and a few unknown devices in the client list are often harmless. The unknown devices are usually smart TVs, printers, phones with randomized hardware addresses or guests. To check, turn off your known devices one by one and see what stays, or look up the manufacturer prefix in the connected-device list. If you want a broader set of symptoms across the computer itself, our guide on warning signs your computer is hacked is a good complement.
If you think the router is compromised: first moves
- Do not log in to banks or work accounts from the home network until the router is clean. Use mobile data for urgent matters.
- Disconnect the router from the internet (unplug the WAN cable) while you work, so that nothing can talk to the attacker.
- Record what you see: take screenshots of DNS, users, port forwards and logs before you reset anything. This is useful for the provider, an insurer or a technician.
- Reset and reconfigure (next section).
- Change passwords for important accounts from a device that you trust, starting with email, bank and any password manager master password. If a device on your network showed certificate warnings, change those passwords too and turn on two-step verification.
- Scan your computers with a reputable security tool, because a router compromise sometimes comes with malware on devices.
Reset and reconfigure checklist
A factory reset followed by a clean setup, not by restoring an old backup, is the dependable way to remove a hidden change from a router. Update the firmware before you reconnect it to the internet, use a new admin password and a new Wi-Fi password, and leave every remote feature off at first. Plan about an hour for a home router and half a day for an office with VLANs and port forwards.
Reset and reconfigure checklist
- I saved screenshots of the current settings (for reference only, not to restore blindly).
- I downloaded the newest firmware for my exact model and hardware version from the vendor, onto a computer I trust.
- I performed a factory reset (reset button held for the time the manual states, or the reset option in the admin page).
- With the WAN cable still unplugged, I signed in with the default login and installed the firmware manually from the file.
- I set a new, long, unique admin password and, where possible, a new admin username.
- I rebuilt internet settings by hand (PPPoE login, VLAN ID, static IP) from my provider's information.
- I created a new Wi-Fi name and a new strong Wi-Fi password (WPA2 or WPA3), and a separate guest network.
- I left remote administration, UPnP, WPS and the VPN server OFF.
- I plugged the WAN cable back in and confirmed DNS is what I expect.
- I re-added only the port forwards I really need, one at a time.
- I reconnected devices and updated their saved Wi-Fi password, including smart-home devices.
- I turned on automatic updates and set a calendar reminder to review the router every three months.
For a MikroTik, the equivalent is to reset the configuration with no default configuration (or keep the default only if you will immediately lock it down), upgrade RouterOS, and re-create the configuration in a clean way. Importing an old export file is risky if you do not know whether it contains the unwanted entries. If the device is a core piece of your business network, this is the moment to ask a professional to rebuild it with a documented, minimal configuration.
Smart-home devices deserve their own pass: cameras, doorbells, plugs and speakers often use the same Wi-Fi password and may need to be re-paired. Our article on how to tell if a router or smart-home device has been hacked lists device-side symptoms and what to do about each.
Three realistic scenarios (illustrative)
These examples are illustrative, not real client cases. They show what the update, the lockdown and the reset typically look like for a family, a home office and a small shop. Numbers are rounded estimates in Canadian dollars.
Scenario 1: Family with an ASUS router bought in 2022 (illustrative)
A family never logged in to their router after setup. Following the steps above, they opened the Firmware Upgrade page and found a version released more than a year before. They installed the newest file from the ASUS support page for their model, turned off web access from the WAN and the unused VPN server, and changed the admin password. Time: about 25 minutes. Cost: 0 CAD. Result: current firmware, fewer services exposed, no reinstall.
Scenario 2: Home office with a MikroTik hAP and SSH open to the internet (illustrative)
A freelancer used a MikroTik at home for a static IP and had SSH reachable from anywhere for convenience. After reading the vendor's advice, they upgraded RouterOS, restricted SSH and WinBox to their own address and a VPN, removed Telnet, FTP and API, and found one old user from a former contractor which they deleted. They exported the clean configuration for later. Time: about 90 minutes. Cost: 0 CAD in software, or about 119.99 CAD if they asked IT Cares for a 60-minute remote session to do it with them.
Scenario 3: Small shop where customers got redirected pages (illustrative)
A small shop noticed that several devices showed certificate warnings for a common email site, while a phone on mobile data did not. The DNS field on the router showed an address nobody recognised, and the admin password was still the factory one. The owner unplugged the WAN cable, took screenshots, reset the router, installed firmware from the vendor, set new passwords and rebuilt the settings. Then they changed email and bank passwords from a trusted phone and turned on two-step verification. Time: roughly half a day including password changes. Lesson: the factory password and open remote administration were the weak points, not the Wi-Fi password.
Small-office router hardening plan
For an office, a hardened router means current firmware, separate networks for staff, guests and devices, no management access from the internet, a documented configuration, and a calendar review every quarter. These controls cost little and prevent most router-related incidents. The same plan fits a home office with a few devices, only simpler.
- Inventory. List every router, firewall, access point and switch with model, hardware version, firmware version, install date and who manages it. Many offices discover a forgotten second router in a closet.
- Patch window. Pick a monthly slot (for example the first Sunday morning) to check vendor pages and install updates. For critical alerts like this week's, patch within days.
- Segment the network. Use at least three networks: staff computers, guest Wi-Fi, and devices such as printers, cameras and smart TVs. Block guest and device networks from reaching staff computers. Our secure business Wi-Fi network guide shows how to plan this.
- Management only from inside. Allow admin logins only from one management computer or a management VLAN. Disable WAN-side administration, Telnet, FTP and the unneeded API services.
- Strong, individual admin accounts. No shared "admin/admin". Store passwords in a business password manager (see our business password manager guide) and enable two-step verification on any cloud management account.
- Remote work through a patched VPN. If staff need access from home, use a maintained VPN solution with named users and certificates or strong keys, and remove ex-employees the day they leave. Keep VPN profiles under control, since a profile is configuration that can do more than people expect.
- Back up the configuration. Export the router configuration after each change and store it offline or in a protected place, with the firmware file you installed. A documented, known-good copy saves hours after a failure.
- Log and alert. Send router logs to a simple log server or at least keep them, and set an alert for admin logins from unfamiliar addresses. Even a free email alert helps.
- Spare unit. For a business that cannot be offline, keep a pre-configured spare router or a mobile hotspot for emergencies.
- Know your obligations. In Quebec, a confidentiality incident involving personal information can trigger duties under Law 25; if you hold customer or patient data, a compromised router should be treated as a possible incident and documented. A cyber-insurance policy may also ask for your patching practices; see our cyber insurance guide for Canadian small businesses.
| Control | Home | Home office | Small office (5 to 25 staff) |
|---|---|---|---|
| Firmware reviewed | Every 3 months, automatic if possible | Monthly | Monthly, plus within days for critical alerts |
| Remote admin from internet | Off | Off | Off, management VLAN only |
| Guest network | Yes | Yes | Yes, plus device network |
| VPN | Usually none | Optional, patched | Named users, reviewed quarterly |
| Configuration backup | Screenshots | Export file | Export plus change log |
| Admin 2-step verification | On cloud account | On | On, plus password manager |
The best use of this week's news is to turn it into a habit. Put "check router firmware" on the same quarterly reminder as testing your backups. A small office that follows these steps is, in our experience, harder to attack than many larger organisations that never review the device at the edge.
Buy or replace: when a router has reached the end
Replace the router when the vendor no longer publishes firmware for it, when it is older than about six or seven years and lacks modern security options such as WPA3 and automatic updates, or when you cannot turn off features that expose it. If it still gets security updates and you can lock it down, updating is enough. A new router is not automatically safer: the key is that the vendor keeps issuing fixes.
| Question | If yes | If no |
|---|---|---|
| Is there a firmware release for my model in the past 12 months? | Keep, update, harden | Plan replacement |
| Does the vendor state a support end date for this model? | Replace before that date | Check the vendor page again in 6 months |
| Can I turn off remote admin, UPnP and WPS? | Keep | Replace or put behind your own firewall |
| Does it support WPA3 and automatic updates? | Fine | Consider replacing at next upgrade |
| Do I need more coverage or more devices than it handles? | Upgrade for performance too | Do not buy only for speed |
| Is it supplied by my provider? | Ask provider about updates | Not applicable |
When you buy, favour brands that publish a support policy, release notes and a security contact, offer automatic updates, and let you sign in with strong account protection. Whether you need Wi-Fi 6E or Wi-Fi 7 depends on your devices and home size; our Wi-Fi 6E and Wi-Fi 7 upgrade guide helps you decide without overspending. If your Wi-Fi misbehaves after changing hardware, our Wi-Fi troubleshooting guide covers the common causes.
Two practical notes. First, do not buy a used router unless you can reset it and install the latest vendor firmware, since the previous owner may have left changes. Second, avoid obscure no-name routers from marketplaces with no firmware page, because you cannot verify support or updates for them.
What it costs in Canada: DIY versus a technician
Updating firmware and closing remote access yourself costs nothing but time, usually 20 to 90 minutes. A new consumer router typically costs from about 100 CAD to several hundred CAD depending on coverage and features, and a professional remote session with IT Cares is 119.99 CAD for a 60-minute Expert Consultation. Router prices change with the market and the retailer, so treat the hardware ranges as rough estimates and check current store prices.
| Option | Typical cost (CAD) | Time | Best for |
|---|---|---|---|
| DIY firmware update and lockdown | 0 | 20 to 90 minutes | Comfortable users with a standard home router |
| Remote session with a technician (Expert Consultation) | 119.99 per 60 minutes | 60 minutes | Update, hardening, signs-of-compromise review, or a clean reset with a guide |
| New consumer router (estimate) | About 100 to 400, varies by model | 1 to 2 hours to set up | Unsupported or very old models |
| Small-office rebuild with segmentation (estimate) | Quote based on size | Half day or more | Offices with VPN, VLANs and customer data |
| Cost of an incident (no estimate) | Hard to predict | Days | Not a figure we can state; prevention is cheaper |
When to call a professional
Call a professional if you found unknown users, scripts, DNS changes or port forwards, if you run a business network with customer data, if you cannot log in to your router, or if the update fails and the internet stays down. A short remote session often settles it in an hour, and you keep watching the screen the whole time.
IT Cares has provided remote and on-site IT support in Quebec and across Canada since 2014. We can check your firmware, restrict management access, review settings for tampering, and walk you through a clean reset. To talk to someone now, call 1 (888) 711-9428 or book a remote session. If you suspect a scam call or fake support message linked to this news, read our guide on what to do after a fake tech support scam first, and never give a stranger remote access to your router.
Official resources to check
Always confirm model-specific details on the vendor's own pages: MikroTik's security advisories for RouterOS, the support page for your exact ASUS model, and CISA's Known Exploited Vulnerabilities catalog for flaws that are listed as exploited. Use these rather than social media posts or forum threads.
- MikroTik security advisories: fixed RouterOS versions and recommendations for the September 2026 issues.
- CISA Known Exploited Vulnerabilities catalog: where CVE-2026-67279 for MikroTik RouterOS appears.
- Your router vendor's support page: search by exact model and hardware version; read the release notes for security fixes.
- Your internet provider: for supplied gateways, ask whether remote management is on and how updates are delivered.
Remember the limits of this guide. We did not read an ASUS advisory, so the ASUS section tells you how to update and harden, not which model is affected. If the vendor page for your model lists a specific fixed version, that is the version to install.
Still stuck? Get a technician on it now
Remote support from IT Cares: we connect to your device, fix it with you watching, and explain what happened.
Frequently asked questions
Related guides
- Home Wi-Fi router security guide
- Signs your router or smart home device is hacked
- Wi-Fi 6E or Wi-Fi 7 router: should you upgrade in 2026?
- Secure business Wi-Fi network guide
- Warning signs your computer is hacked
- Wi-Fi troubleshooting guide
- Business password manager guide
- How to set up two-factor authentication
Sources and official references
Last verified: October 1, 2026
- MikroTik security advisories (opened 2026-10-01): September 2026 critical issue, CVE-2026-52346
- CISA Known Exploited Vulnerabilities catalog (opened 2026-10-01): CVE-2026-67279 entry
- MikroTik downloads page (opened 2026-10-01; version details not displayed)
- ASUS product security advisory page (opened 2026-10-01; advisory content not displayed)
