FCC Bans New Foreign-Made Routers Over Supply Chain and Cyber Risk Concerns
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得通读整篇文章,抓住主要信息。 文章讲的是美国FCC禁止进口新的外国制造的消费级路由器,原因是出于网络安全和国家安全的考虑。FCC主席提到这是为了保护美国的通信网络,而这一决定是基于行政部门的安全评估。 接下来,文章提到所有外国生产的路由器都被加入到受管制名单中,除非获得国防部或国土安全部的有条件批准。目前只有几家公司的产品获得批准,而Starlink路由器因为在美国生产而豁免。 此外,文章指出外国路由器可能带来的供应链漏洞和严重的网络安全风险,包括被用于网络间谍活动和破坏关键基础设施。FCC还提到一些中国相关的威胁行为者利用这些路由器进行攻击。 最后,文章说明这次禁令不影响已经购买的路由器或零售商继续销售已获批的型号。 总结时要涵盖FCC的决定、原因、受影响的产品以及例外情况。同时要注意用词简洁,确保在100字以内。 </think> 美国联邦通信委员会(FCC)宣布禁止进口新的外国制造消费级路由器,以应对网络安全和国家安全风险。该禁令基于行政部门的安全评估,并将所有外国生产的路由器加入受管制名单,除非获得有条件批准。目前仅部分无人机系统和软件定义无线电设备获准。该政策不影响已购买或已获批型号的销售。 2026-3-25 07:11:0 Author: thehackernews.com(查看原文) 阅读量:4 收藏

Network Security / Data Protection

The U.S. Federal Communications Commission (FCC) said on Monday that it was banning the import of new, foreign-made consumer routers, citing "unacceptable" risks to cyber and national security.

The action was designed to safeguard Americans and the underlying communications networks the country relies on, FCC Chairman Brendan Carr said in a post on X. The development means that new models of foreign-produced routers will no longer be eligible for marketing or sale in the U.S. The move comes in the wake of a national security determination provided by Executive Branch Agencies, Carr added.

To that end, all consumer-grade routers manufactured in foreign countries have been added to the Covered List, unless they have been granted a Conditional Approval by the Department of War (DoW) or the Department of Homeland Security (DHS) after determining that they do not pose any risks.

As of writing, the approved list only includes drone systems and software-defined radios (SDRs) from SiFly Aviation, Mobilicom, ScoutDI, and Verge Aero. Producers of consumer-grade routers can submit an application for Conditional Approval. According to BBC News, Starlink Wi-Fi routers are exempt from the policy, as they are made in the U.S. state of Texas.

"The Executive Branch determination noted that foreign-produced routers (1) introduce 'a supply chain vulnerability that could disrupt the U.S. economy, critical infrastructure, and national defense' and (2) pose 'a severe cybersecurity risk that could be leveraged to immediately and severely disrupt U.S. critical infrastructure and directly harm U.S. persons,'" the FCC said.

The agency said both state and non-state sponsored threat actors have exploited security shortcomings in small and home office routers to break into American households, disrupt networks, facilitate cyber espionage, and enable intellectual property theft. Furthermore, these devices could be conscripted into massive networks with the goal of carrying out password spraying and unauthorized network access, as well as acting as proxies for espionage.

China-nexus adversaries such as Volt Typhoon, Flax Typhoon, and Salt Typhoon have also been observed leveraging botnets comprising foreign-made routers to conduct cyber attacks on critical American communications, energy, transportation, and water infrastructure.

"In Salt Typhoon attacks, state-sponsored cyber threat actors leveraged compromised and foreign-produced routers to jump to embed and gain long-term access to certain networks and pivot to others depending on their target," according to the National Security Determination (NSD).

Also highlighted by the U.S. government is a botnet dubbed CovertNetwork-1658 (aka Quad7), which has been used to orchestrate highly evasive password spray attacks. The activity is assessed to be the work of a Chinese threat actor tracked as Storm-0940.

It's worth noting that the Covered List update does not affect a customer's continued use of routers that were already purchased. Nor does it impact retailers, who can continue to sell, import, or market router models that were approved previously through the FCC's equipment authorization process.

"Unsecure and foreign-produced routers are prime targets for attackers and have been used in multiple recent cyber attacks to enable hackers to gain access to networks and use them as launching pads to compromise critical infrastructure," the NSD said. "The vulnerabilities introduced into American networks and critical infrastructure resulting from foreign-manufactured routers are unacceptable."

Routers have been a lucrative target for cyber attacks, as they serve as the primary conduit for internet access. Compromised routers could allow threat actors to conduct network surveillance, exfiltrate data, and even deliver malware to victims. In 2014, journalist Glenn Greenwald alleged in his book No Place to Hide how the U.S. National Security Agency (NSA) routinely intercepts routers before U.S. manufacturers can export them in order to implant backdoors.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/03/fcc-bans-new-foreign-made-routers-over.html
如有侵权请联系:admin#unsafe.sh