Skip to main content
  1. Home
  2. Computing
  3. News

Secondhand routers may be a serious security concern

Add as a preferred source on Google

Security researchers have publicly revealed findings in a study that uncovered that more than half of the enterprise routers sold secondhand to online resellers, such as eBay, had not been factory reset and wiped of their data. This means the devices still contained sensitive company information from their previous owners when they were resold.

Researchers from the security firm ESET plan to showcase their study at the RSA security conference in San Francisco next week, but told Wired that they were able to uncover data of the enterprise organizations from the secondhand routers, including “network information, credentials, and other confidential data,” with no major effort.

A Wi-Fi router with an ethernet cable plugged in.
wlan antenna Getty Images

In particular, the researchers purchased 18 used routers from well-known brands including Cisco, Fortinet, and Juniper Networks. They ultimately discovered that nine of the devices were sold as is, and they offered easy access to all the router’s information. Meanwhile, five of the routers had been fully factory reset and wiped of all data. Two of the routers were encrypted, one was dead, and one was a mirror copy of another device, Wired noted.

Recommended Videos

The information ESET researchers were able to collect from the nine unprotected routers includes “credentials for the organization’s VPN, credentials for another secure network communication service, and hashed root administrator passwords.”

Eight of the unprotected routers included “router-to-router authentication keys” with “information about how the router connected to specific applications used by the previous owner.” Four routers included “credentials for connecting to the networks of other organizations, such as trusted partners, collaborators, or other third parties.” Three devices hosted details of how one could “connect as a third party to the previous owner’s network,” while two held customer data, according to the study.

ESET also noted that all nine unprotected routers included enough data for the researchers to figure out to which organizations they previously belonged.

The researchers noted how much of a security risk these routers being so easily accessible is because of the prevalence of cybercriminals and state-backed hackers. The routers can simply be purchased at a discount online because they are secondhand, and bad actors can potentially scan devices for valuable corporate information they can sell on the dark web and then simply resell the router again. The researchers said they hesitated to release their findings, but ultimately decided that awareness was the better option.

The ESET team told Wired they have done their diligence to contact and warn the prior owners of the nature of their routers, with some grateful for the update. Meanwhile, others appeared to ignore the warnings or not cooperate.

Fionna Agomuoh
Fionna Agomuoh is a Computing Writer at Digital Trends. She covers a range of topics in the computing space, including…
OpenRGB 1.0 is finally here, and it wants to end your RGB software headaches
No more juggling five different apps just to make your keyboard glow the right color.
A PC featuring Lian Li's wireless RGB ecosystem showcased at Computex 2024.

Anyone who has dealt with gaming peripherals knows the RGB software struggle is real. Every brand wants you to install its own app, and most of these run quietly in the background, eating up resources just to keep your lights synced. OpenRGB has been trying to fix this mess for years, and the project just hit a big milestone with the release of version 1.0.

What's new in OpenRGB 1.0?

Read more
Apple’s new child safety tools are now available with better controls for screen time, web access, and harmful content
Parents can now start child accounts with a smaller set of approved apps and add more access later
Apple child safety features revealed at WWDC 2026

Apple first previewed a new set of child safety features at WWDC in June, and parents can now start using them with iOS 27, iPadOS 27, and macOS 27. The update gives families more control over which apps children can access, what websites they can visit, who they can communicate with, and how much time they spend in certain app categories.

Apple is also changing Screen Time to make those controls easier to manage. Parents get a clearer view of device usage, quicker access to restrictions, and age-based guidance for setting limits across categories such as Games, Social Media, and Entertainment.

Read more
Your NVIDIA RTX PC can now run Perplexity’s AI agent locally
Portable Computer brings agentic AI to Windows, with cloud escalation only when needed.
Perplexity and NVIDIA Partnership

Perplexity and NVIDIA are bringing Portable Computer to Windows PCs, giving owners of compatible GeForce RTX and RTX PRO machines a local AI agent that can actually get things done. The catch is hardware: Windows support requires an NVIDIA GPU with 24GB or more of VRAM.

Think of it as an AI co-worker that doesn't need the cloud for everything

Read more