If your router still works, why replace it?
That logic has kept countless aging internet-connected devices alive long past their intended lifespan. Old wi-fi routers keep humming in closets. Security cameras continue watching front porches. Forgotten network equipment soldiers on for years after manufacturers stop supporting it.
New research from Arizona State University suggests that many of those devices may still be vulnerable to publicly known cyberattacks, and their owners likely have no idea.
Hui Jun Tay, a computer science doctoral student focused on cybersecurity in the School of Computing and Augmented Intelligence, part of the Ira A. Fulton Schools of Engineering at ASU, led the study and presented its findings at the 2026 Institute of Electrical and Electronics Engineers Symposium on Security and Privacy, earning a Distinguished Paper Award at the conference.
The research challenges one of cybersecurity’s most trusted assumptions — that responsible disclosure reliably protects users once a vulnerability becomes public. For many years, the process has been considered a cornerstone of cybersecurity. Researchers who discover a flaw typically report it privately to a vendor, giving the company time to investigate, identify affected products and develop a fix before details are released publicly. The idea is to patch the hole before attackers can exploit it.
Working under the supervision of Yan Shoshitaishvili and Fish Wang, both Fulton Schools associate professors of computer science and engineering, Tay and collaborators found that millions of devices may be slipping through the gaps in that process.
“We kept finding these overlaps where the same vulnerability affected multiple devices, but only some of the devices were reported,” Tay says. “That made us wonder how many more are out there? We decided to measure it, and the answer was pretty bad.”
Old routers never die
Their research uncovered 422 previously unknown combinations of vulnerable devices and publicly available attack methods across internet-connected routers and cameras. More alarmingly, they estimate that more than one million devices currently connected to the internet may still be vulnerable, even when running the most up-to-date software available from their manufacturers.
To reach that conclusion, the team conducted a sweeping analysis of thousands of routers and cameras from major manufacturers. They examined 3,569 versions of device software spanning 566 different models, then tested dozens of known cyberattack techniques against them to see whether vulnerabilities extended beyond the devices officially identified in security advisories.
What they discovered was a cybersecurity version of an iceberg — with known vulnerabilities just visible at the tip and a much larger number of affected devices remaining hidden beneath the surface. And many of those hidden devices share a common characteristic.
They’re old.
The team found that a large portion of the vulnerable devices had reached end-of-life status, meaning manufacturers no longer provide updates or security support. However, hardware remains very much alive in homes and businesses.
“People might not even be aware that it’s expired,” Tay says. “There isn’t like a giant warning label that flashes up.”
That reality helps explain why the numbers are so large. Routers and cameras are unlike smartphones, which consumers tend to replace every few years. Network hardware often stays in service for six, eight or even ten years. If it still connects to the internet, most people see little reason to replace it.
Read the full story on Engineering News.