The Federal Communications Commission (FCC) moved to ban imports of all foreign-produced routers over “unacceptable risks to national security.”
A public notice dated March 23 extends the import ban to consumer-grade devices produced outside the U.S. The move does not impact any previously-purchased consumer-grade routers, the FCC confirmed, with consumers still able to use devices they’ve already acquired.
The FCC contends that foreign-made routers introduce “a supply chain vulnerability that could disrupt the U.S. economy, critical infrastructure, and national defense,” while also posing “a severe cybersecurity risk that could be leveraged to immediately and severely disrupt U.S. critical infrastructure and directly harm U.S. persons.”
FCC Chairman Brendan Carr welcomed the decision, saying: “Following President Trump’s leadership, the FCC will continue [to] do our part in making sure that U.S. cyberspace, critical infrastructure, and supply chains are safe and secure.”
The move sees foreign-produced routers added to what’s known as the "Covered List," a catalogue of communications equipment and services.
Among the items already subject to the list are telecom equipment from both Huawei and ZTE, following prior bans, and cybersecurity and anti-virus software produced by Kaspersky Lab after a ban imposed by President Trump during his first term over alleged ties with state-sponsored espionage programs in Russia.
Foreign-made routers that receive conditional approval from either the Department of Defense (DOD) or the Department of Homeland Security (DHA) are, however, suitable for import.
The sweeping move was made in the wake of cyberattacks like the China-linked Salt Typhoon that hacked major communication networks from the likes of AT&T, Verizon, and Lumen Technologies. Threat actors behind the notorious 2024 attacks are believed to have resurfaced earlier this year, targeting congressional staff email accounts.
The FCC’s ban references Salt Typhoon and other cyberattacks as a catalyst for the decision, contending security gaps in foreign-made routers were exploited to “attack American households, disrupt networks, enable espionage, and facilitate intellectual property theft.”
Commenting on the decision, Phosphorus president and COO, Sonu Shankar, said the ban was “an important step toward addressing risks tied to limited visibility into foreign manufacturing processes and assembly sites.”
“Organizations often lack insight into how devices are built or whether they have been tampered with before deployment. Even devices assembled in the U.S. frequently rely on globally sourced components, extending that uncertainty across the supply chain. Firmware from banned manufacturers has repeatedly surfaced in white-labeled or OEMed products, making them difficult to identify and manage with traditional approaches.
“Risk is not static. A device that appears trusted today can become weaponized if the firmware update channel gets compromised. We need to get back to the fundamentals. For consumers, password and firmware updates are important. For enterprise customers, this means continuous assessment, firmware-level validation that the device is not banned, and consistent enforcement of credential, firmware, certificate and configuration hygiene.”
Comments