Researchers race against routers and hackers

Award-winning ASU research reveals more than one million vulnerable routers and cameras still online.

If your router still works, why replace it?

That logic has kept countless aging internet-connected devices alive long past their intended lifespan. Old wi-fi routers keep humming in closets. Security cameras continue watching front porches. Forgotten network equipment soldiers on for years after manufacturers stop supporting it.

New research from Arizona State University suggests that many of those devices may still be vulnerable to publicly known cyberattacks, and their owners likely have no idea.

Hui Jun Tay, a computer science doctoral student focused on cybersecurity in the School of Computing and Augmented Intelligence, part of the Ira A. Fulton Schools of Engineering at ASU, led the study and presented its findings at the 2026 Institute of Electrical and Electronics Engineers Symposium on Security and Privacy, earning a Distinguished Paper Award at the conference.

The research challenges one of cybersecurity’s most trusted assumptions — that responsible disclosure reliably protects users once a vulnerability becomes public. For many years, the process has been considered a cornerstone of cybersecurity. Researchers who discover a flaw typically report it privately to a vendor, giving the company time to investigate, identify affected products and develop a fix before details are released publicly. The idea is to patch the hole before attackers can exploit it.

Working under the supervision of Yan Shoshitaishvili and Fish Wang, both Fulton Schools associate professors of computer science and engineering, Tay and collaborators found that millions of devices may be slipping through the gaps in that process.

“We kept finding these overlaps where the same vulnerability affected multiple devices, but only some of the devices were reported,” Tay says. “That made us wonder how many more are out there? We decided to measure it, and the answer was pretty bad.”

Old routers never die

Their research uncovered 422 previously unknown combinations of vulnerable devices and publicly available attack methods across internet-connected routers and cameras. More alarmingly, they estimate that more than one million devices currently connected to the internet may still be vulnerable, even when running the most up-to-date software available from their manufacturers.

To reach that conclusion, the team conducted a sweeping analysis of thousands of routers and cameras from major manufacturers. They examined 3,569 versions of device software spanning 566 different models, then tested dozens of known cyberattack techniques against them to see whether vulnerabilities extended beyond the devices officially identified in security advisories.

What they discovered was a cybersecurity version of an iceberg — with known vulnerabilities just visible at the tip and a much larger number of affected devices remaining hidden beneath the surface. And many of those hidden devices share a common characteristic.

They’re old.

The team found that a large portion of the vulnerable devices had reached end-of-life status, meaning manufacturers no longer provide updates or security support. However, hardware remains very much alive in homes and businesses.

“People might not even be aware that it’s expired,” Tay says. “There isn’t like a giant warning label that flashes up.”

That reality helps explain why the numbers are so large. Routers and cameras are unlike smartphones, which consumers tend to replace every few years. Network hardware often stays in service for six, eight or even ten years. If it still connects to the internet, most people see little reason to replace it.

When good security creates bad opportunities

The researchers say the most surprising finding wasn’t simply that old devices remain vulnerable. It’s what happens after those vulnerabilities become public.

Responsible disclosure is designed to help defenders. Yet the study suggests the process can create an unintended asymmetry. By addressing a vulnerability publicly, researchers often release technical details or proof-of-concept code showing how the flaw works. The goal is to help other security professionals verify the issue and improve defenses.

But attackers can read those same reports.

“It’s like watching videos of lock-picking techniques,” Tay says. “Somebody could just look at the video and say, ‘Oh, wow, this looks like the lock that so-and-so uses to secure their gate down the street.'”

An attacker doesn’t necessarily need to know which products a vendor officially lists as vulnerable. They only need to understand how the flaw works. Armed with publicly released information about attack methods, hackers can search for other devices built with similar software and test whether the same weakness exists there.

The paper describes an “invisible gap” between the devices vendors acknowledge as vulnerable and the larger universe of devices that may actually be affected. End users see only the official list. Attackers, meanwhile, can often see a roadmap to finding additional targets.

A single compromised router can be added to a network of hijacked devices and can be used to overwhelm websites with traffic, disrupt online services or even generate cryptocurrency. Multiply that by hundreds of thousands of vulnerable devices, and the computing power adds up quickly. A compromised security camera could also give attackers control over the device itself or a foothold for further attacks.

The study doesn’t suggest that responsible disclosure should stop. Instead, it highlights the importance of understanding its limitations.

“Everyone assumed there was a gap between the devices we know are vulnerable and the devices that are actually vulnerable,” Shoshitaishvili says. “The contribution of this research is that we measured it against long-standing assumptions and norms of how the cybersecurity community operates. Once you can see the size of the problem, you can start designing solutions for it.”

The findings also offer a practical takeaway. Routers and security cameras often stay in service long after people stop thinking about them. Tay recommends checking whether devices are still supported by their manufacturers and keeping firmware up to date. As a general rule, replacing a device every four to five years can help reduce the risk of relying on aging hardware that no longer receives security updates.

Portrait of Kelly DeVos

Kelly deVos

Kelly deVos is the communications specialist for the School of Computing and Augmented Intelligence. She holds a B.A. in Creative Writing from Arizona State University. Her work has been featured in the New York Times as well as on Vulture, Salon and Bustle. She is a past nominee for the Georgia Peach, Gateway and TASHYA book awards.

Media contact: 480-329-4455Ira. A Fulton Schools of Engineering