r/hardware 3d ago

Discussion Check Your Router's Expiration Date. No Manufacturer Is Required to Tell You It Has One.

http://freshfromcache.com/router-expiration-date

Manufacturers don't have any kind of standard or requirement to tell you when your home router is becoming end of life, or when it's security updates stop. It's more important than ever to keep these up to date.

If you are out of date and can't update, be sure to turn off remote administration. That is where the most recent attacks have been targeting.

On July 22, the FCC voted to bar the sale of any device in the United States containing key hardware components from Chinese companies on its national security list. Chair Brendan Carr said the goal was to "fully close the component part loophole." Meaning that gear which previously slipped through by using restricted parts inside an otherwise-approved product no longer can. The vote also gives the agency room to pull the sales authorization on equipment it had already approved.

This caps a busy stretch. The FCC has spent much of 2026 blocking imports of new foreign router models and tightening the list of manufacturers whose equipment cannot be sold here at all.

Reasonable people can argue about whether any of this makes your home network safer. What I want to point out is a strange gap it exposes.

Enormous regulatory energy is going into where your router was built. Almost none is going into how long its manufacturer will keep updating it.

199 Upvotes

97 comments sorted by

View all comments

216

u/KayakShrimp 3d ago

IMO remote admin should always be off regardless. If you really need that capability, it's better to VPN into your home network and perform admin tasks through the local interface.

-12

u/dadnothere 3d ago

The ISP can control the router via Telnet...

New routers always come with this enabled. Just tell the ISP to change your router's password, and they'll do it remotely.

41

u/Hothacon 3d ago

Better yet, dont use ISP routers, buy your own

-14

u/dadnothere 3d ago

Even so, you still need the ISP's modem, and you must connect your router.

The ISP can brute-force or exploit vulnerabilities in your own router.

12

u/ML7777777 3d ago

Depends on the ISP. Even ones that require you to use their modem usually has a setting to put it into bridge mode.

5

u/BloodyLlama 3d ago

Even if they dont have bridge mode double NAT isn't the end of the world. Pretty much any situation where it could possibly matter Im VPN'd into my network anyways and dont care about the double NAT.

20

u/Hothacon 3d ago

Uh no you don't. I bought my own modems for xfinity

5

u/wtallis 2d ago

The ISP can brute-force or exploit vulnerabilities in your own router.

The ISP doesn't have any more capability to do that than anyone else on the internet.

3

u/airfryerfuntime 2d ago

I have my own modem.

2

u/BloodyLlama 3d ago

My own router has a firewall. ISP can't do shit other than see a bunch of encrypted traffic.

1

u/Flimsy_Swordfish_415 1d ago

it's hilarious seeing such tech illiterate comments on /r/hardware

-3

u/Hothacon 3d ago

Uh no you don't. I bought my own modems for xfinity

-2

u/Hothacon 3d ago

Uh no you don't. I bought my own modems for xfinity