Table of Contents
On March 24, 2026, the US Federal Communications Commission made a sweeping decision: all new consumer routers manufactured outside the United States are now banned from import and sale. Added to the FCC’s Covered List, the regulatory mechanism that blocks equipment from receiving authorisation for the US market, the move effectively closes the door on foreign-made networking gear going forward.
It is a significant policy moment. The FCC cited the Volt Typhoon, Flax Typhoon, and Salt Typhoon attacks, sustained campaigns attributed to Chinese state-sponsored actors that exploited router vulnerabilities to penetrate American critical infrastructure, telecommunications networks, and the homes of private citizens, as the direct justification. FCC Chair Brendan Carr stated that “routers produced abroad were directly implicated in the Volt, Flax, and Salt Typhoon cyberattacks which targeted critical American communications, energy, transportation, and water infrastructure.”
The problem is this: the ban protects future purchases. It does nothing about the millions of foreign-made routers already deployed on home networks across the country, including on the home networks of your remote workforce.
What the Ban Actually Does and Doesn’t Do
The mechanics of the FCC ruling are important to understand clearly. Adding a device to the Covered List prevents it from receiving new equipment authorisation, which is required for import, marketing, or sale in the US. New models of foreign-made routers cannot enter the market. Existing, previously authorised models remain in legal use. Consumers are not required to replace their current devices. Software updates for existing covered devices are permitted at least through March 1, 2027.
China controls an estimated 60% of the US home router market. The ban is not China-specific, it applies to any router manufactured in any foreign country, but the scale of currently deployed Chinese-manufactured routers is the underlying concern. Those devices are not going away. They will continue to sit on home networks, connected to corporate laptops, used by remote workers, for years to come.
The FCC did not provide evidence that US-made consumer routers are inherently more secure than foreign alternatives. Independent security researchers have noted a hard truth: most Volt Typhoon attacks cited in the FCC’s justification primarily targeted Cisco and Netgear hardware, both US-designed companies. Router vulnerabilities are, at their core, a software maintenance problem. When manufacturers stop pushing security updates to older models, those devices become permanently exposed, regardless of where they were assembled.
The Threat That Is Already Inside Your Extended Perimeter
The Typhoon campaigns are not hypothetical. They are the most sustained and sophisticated series of network infrastructure attacks ever attributed to a state actor.
Salt Typhoon has compromised over 600 organisations across more than 80 countries since 2019. In late 2024, it penetrated the networks of major US telecommunications providers, Verizon, AT&T, and Lumen Technologies, using router vulnerabilities for initial access, then establishing persistent footholds to intercept communications of significant political figures and lawful intercept targets. Between December 2024 and January 2025, Recorded Future’s Insikt Group identified Salt Typhoon exploiting unpatched Cisco devices globally, leveraging CVE-2023-20198 for initial access before using CVE-2023-20273 to gain root privileges.
Flax Typhoon specifically targets IoT devices and internet-facing servers as entry points. Its defining characteristic is the construction of botnets from compromised IoT devices, cameras, DVRs, routers, to serve as command-and-control infrastructure. The US government disrupted one such botnet in September 2024. Another was already being deployed days later.
Volt Typhoon has been documented targeting US critical infrastructure including energy, transportation, and water systems, using compromised home and small office routers as intermediate relay points, a technique that makes the attacker’s traffic appear to originate from legitimate residential IP addresses.
These operations share a common thread: the compromised router is not usually the final target. It is the stepping stone. It is the quiet presence on a home network that goes unnoticed while traffic is redirected, credentials are harvested, and lateral movement begins.
The Visibility Gap That Policy Cannot Close
Here is the operational reality for enterprise security teams in 2026: your remote workers’ home networks are not within your security perimeter, but they are absolutely within your threat surface.
A managed corporate laptop connects to a home network via a router that IT has never seen, does not monitor, and cannot assess. That router may be running firmware from 2022. It may be a model that the manufacturer stopped updating eighteen months ago. It may have been quietly recruited into a botnet overnight. Your EDR tool does not see it. Your SIEM has no telemetry from it. Your vulnerability management programme does not include it.
According to Forescout’s 2026 Riskiest Devices research, the router remains the single highest-risk IT device category, with an average of 32 vulnerabilities per router or switch. That figure represents devices that are, in most cases, entirely invisible to the enterprise security programmes responsible for protecting the organisations those devices connect to.
The FCC ban addresses the supply chain for future routers. It does not close this visibility gap. Closing that gap requires a fundamentally different approach — one that makes the home network as observable as the corporate network.

Proactive Visibility: Seeing the Router Before the Attacker Does
The core principle behind 4Remote is straightforward: you cannot protect what you cannot see. The platform provides agentless discovery and continuous monitoring of every device on a remote worker’s home network, including the router that sits at the centre of it.
When a router appears in the 4Remote dashboard, security teams can see its make, model, and firmware version. They can identify devices running outdated software — the single most common precondition for router compromise. They can receive alerts when a device’s network behaviour changes in ways consistent with compromise: unusual outbound connections, DNS changes, unexpected traffic volumes. They can correlate a flagged device with the remote worker whose laptop shares that network, and act before any lateral movement reaches corporate systems.
This is the proactive dimension that the FCC ruling, for all its significance, cannot provide. Policy restricts what routers can be sold tomorrow. Visibility tells you what is happening on the networks your business depends on today.
In the Typhoon scenario specifically, 4Remote’s continuous monitoring provides the earliest possible signal. A router that begins behaving as a relay, forwarding traffic to unexpected external endpoints, responding to unusual command queries, establishing persistent connections, is detectable. Without a tool that watches home network device behaviour, that signal simply does not exist in any security workflow.
4Remote works alongside existing enterprise security stacks, EDR, SIEM, ZTNA, MDM, extending their effective reach into the environment those tools were never designed to cover. The Professional, Enterprise, and Network editions each offer router-level visibility scaled to the needs of organisations of different sizes and complexity.
The Ban Is the Beginning, Not the Answer
The FCC’s decision to ban new foreign-made routers is a policy response to a documented, serious threat. It reflects a genuine understanding that the home router is a national security concern, not merely a consumer product. That framing is correct.
But the lesson from the Typhoon campaigns, from the Aisuru and KimWolf botnet disruptions, from every major router-based intrusion of the past three years, is consistent: the device that causes the breach is almost always one that nobody was watching.
Millions of foreign-made routers remain deployed. They will not be replaced overnight. The attacks targeting them did not pause for the FCC announcement. A new Mirai-derived botnet targeting Android-based set-top boxes was reported in active deployment on March 18 , two days before the most recent law enforcement action concluded.
The organisations that will manage this risk most effectively are not those waiting for policy to solve a visibility problem. They are those that have already decided to look.
Key Takeaways
- The FCC banned all new foreign-made consumer routers (March 24, 2026), citing Volt, Flax, and Salt Typhoon attacks on US critical infrastructure and home networks but existing devices remain in legal use indefinitely.
- China manufactures approximately 60% of US home routers currently in deployment. Those devices are already on your remote workers’ networks and will not be replaced by this ruling.
- Salt Typhoon alone compromised 600+ organisations in 80+ countries, using router vulnerabilities as initial access points for sustained espionage campaigns targeting telecoms, government, and critical infrastructure.
- The real vulnerability is a software maintenance problem, not purely a manufacturing one — any router that stops receiving firmware updates becomes permanently exposed, regardless of origin.
- Enterprise security tools have no visibility into home network routers, 4Remote’s agentless platform discovers every device on remote worker home networks, monitors router behaviour continuously, and surfaces compromise signals before lateral movement can begin.
See Every Router on Your Remote Workers’ Networks
The router in your remote worker’s home office is the front door to your corporate environment. The FCC has changed what can be sold tomorrow. 4Remote lets you see what is running today.
Request a demo to see how 4Remote’s Professional, Enterprise, or Network edition maps every device on your distributed workforce’s home networks, and gives your security team the visibility to act before a router becomes a liability.
Sources: FCC Covered List Update — FCC.gov · US bans foreign routers — The Register · FCC Bans Router Imports — TechCrunch · FCC Bans Foreign Routers — Gizmodo · Salt Typhoon breaches 600 orgs — The Hacker News · RedMike/Salt Typhoon analysis — Recorded Future · Rise of Chinese APT Campaigns — Eclypsium · Riskiest Devices 2026 — Help Net Security
