element14 Community
element14 Community
    Register Log In
  • Site
  • Search
  • Log In Register
  • About Us
  • Community Hub
    Community Hub
    • What's New on element14
    • Feedback and Support
    • Benefits of Membership
    • Personal Blogs
    • Members Area
    • Achievement Levels
  • Learn
    Learn
    • Ask an Expert
    • eBooks
    • element14 presents
    • Learning Center
    • Tech Spotlight
    • STEM Academy
    • Webinars, Training and Events
    • Learning Groups
  • Technologies
    Technologies
    • 3D Printing
    • FPGA
    • Industrial Automation
    • Internet of Things
    • Power & Energy
    • Sensors
    • Technology Groups
  • Challenges & Projects
    Challenges & Projects
    • Design Challenges
    • element14 presents Projects
    • Project14
    • Arduino Projects
    • Raspberry Pi Projects
    • Project Groups
  • Products
    Products
    • Arduino
    • Avnet Boards Community
    • Dev Tools
    • Manufacturers
    • Multicomp Pro
    • Product Groups
    • Raspberry Pi
    • RoadTests & Reviews
  • Store
    Store
    • Visit Your Store
    • Choose another store...
      • Europe
      •  Austria (German)
      •  Belgium (Dutch, French)
      •  Bulgaria (Bulgarian)
      •  Czech Republic (Czech)
      •  Denmark (Danish)
      •  Estonia (Estonian)
      •  Finland (Finnish)
      •  France (French)
      •  Germany (German)
      •  Hungary (Hungarian)
      •  Ireland
      •  Israel
      •  Italy (Italian)
      •  Latvia (Latvian)
      •  
      •  Lithuania (Lithuanian)
      •  Netherlands (Dutch)
      •  Norway (Norwegian)
      •  Poland (Polish)
      •  Portugal (Portuguese)
      •  Romania (Romanian)
      •  Russia (Russian)
      •  Slovakia (Slovak)
      •  Slovenia (Slovenian)
      •  Spain (Spanish)
      •  Sweden (Swedish)
      •  Switzerland(German, French)
      •  Turkey (Turkish)
      •  United Kingdom
      • Asia Pacific
      •  Australia
      •  China
      •  Hong Kong
      •  India
      •  Korea (Korean)
      •  Malaysia
      •  New Zealand
      •  Philippines
      •  Singapore
      •  Taiwan
      •  Thailand (Thai)
      • Americas
      •  Brazil (Portuguese)
      •  Canada
      •  Mexico (Spanish)
      •  United States
      Can't find the country/region you're looking for? Visit our export site or find a local distributor.
  • Translate
  • Profile
  • Settings
Internet of Things
  • Technologies
  • More
Internet of Things
Forum Which trustworthy home or small business router will you choose in year 2025?
  • Blog
  • Forum
  • Documents
  • Quiz
  • Events
  • Polls
  • Members
  • Mentions
  • Sub-Groups
  • Tags
  • More
  • Cancel
  • New
Join Internet of Things to participate - click to join for free!
Actions
  • Share
  • More
  • Cancel
Forum Thread Details
  • State Suggested Answer
  • Replies 16 replies
  • Answers 1 answer
  • Subscribers 502 subscribers
  • Views 3084 views
  • Users 0 members are here
  • TP-Link ransomeware
Related

Which trustworthy home or small business router will you choose in year 2025?

HKPhysicist
HKPhysicist 9 months ago

U.S. Considers Ban On Chinese Made TP-Link Routers

https://www.forbes.com/sites/larsdaniel/2024/12/18/us-considers-ban-on-chinese-made-tp-link-routers-heres-why/

Federal agencies, including the Departments of Commerce, Defense, and Justice, have launched investigations into TP-Link following reports of its routers being exploited in cyberattacks allegedly linked to Chinese state actors. A recent Microsoft Report revealed that compromised TP-Link devices were used in ransomware operations, fueling concerns about the company’s role in facilitating cyber threats.

I have been using their home routers for many years.  Please recommend a trustworthy one to me.  Confounded

  • Sign in to reply
  • Cancel

Top Replies

  • cstanton
    cstanton 9 months ago +6
    Regardless of the router's manufacturer, it is always worth checking if you can flash it with a custom ROM based on open software. For example https://openwrt.org/ , https://dd-wrt.com/ and then also…
  • HKPhysicist
    HKPhysicist 9 months ago in reply to vmate +4
    I have found cheap alternatives: D-Link: made in Taiwan MikroTik: made in Latvia (EU member) Teltonika: made in Lithuania (EU member) Should you need a cheap wireless routers, you may also consider…
  • HKPhysicist
    HKPhysicist 9 months ago in reply to colporteur +3
    It is hard to believe network company security level is so low, lower than my own small public server which only accepts non-root SSH key login!!!
  • anniel747
    0 anniel747 9 months ago

    Cisco and HPE routers are patched rapidly.

    • Cancel
    • Vote Up 0 Vote Down
    • Sign in to reply
    • Verify Answer
    • Reject Answer
    • Cancel
  • JWx
    0 JWx 9 months ago in reply to anniel747

    I have heard many stories about big and well known names having - for example - hard coded passwords or other (random or even seemingly intentional) vulnerabilities/backdoors...

    (maybe in a little sarcastic way) I would say - find a company accused of being a national security treat, whose source code was for the long time shared with western security agencies but despite this fact no hard evidence was ever presented to the general public Slight smile They have the most to lose if they present some sloppy security practices or even intentional backdoors... 

    or - as something more realistic - find hardware that can be flashed using alternative software (like openwrt), this way you are limiting your attack surface (as having something unfamiliar to the attacker) - at least as long as you patch it regularly and until it goes out of support (but usually alternative software supports the hardware long after the manufacturer decides to cease updating it)

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • anniel747
    0 anniel747 9 months ago in reply to JWx

    Many have hard coded backdoors, monitoring or spies in silicon that firmware or software does not affect.

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • vmate
    0 vmate 9 months ago

    I got a Cisco ISR 1111 used for relatively cheap, and had no problems with it so far. It doesn't have 10Gig ports unfortunately though.

    For a DIY option, ultra small form factor PCs (Lenovo's M720q Tiny for example) with a dual/quad PCIe network card, running OPNsense or VyOS work great.

    Mikrotik has amazing hardware and software for super cheap, even when bought brand new, so that is a great choice as well. Some of them also have WiFi, so no need for a separate access point (hAP ax3 for example)

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • HKPhysicist
    0 HKPhysicist 9 months ago in reply to vmate

    I have found cheap alternatives:

    D-Link: made in Taiwan

    MikroTik: made in Latvia (EU member)

    Teltonika: made in Lithuania (EU member)

    Should you need a cheap wireless routers, you may also consider their products.  I have a Mikrotik LTE router.  It is very compact and firmware is updated every few months.

    My first home router is a D-Link.  Then, I used TP-Link wireless routers exclusively because of their cheap prices.  Now, it is time to change.

    • Cancel
    • Vote Up +4 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • JWx
    0 JWx 9 months ago in reply to anniel747

    In my opinion this is not common - most of them are basic [read - low cost] applications of SoCs made by big Taiwanese manufacturers (like Atheros or Mediatek), and if those are hardware backdoored we are all toast... For example, Mediatek chipsets are used in some TP-Link routers - and in more than twenty different manufacturer's hardware also (including Ubiquiti and Linksys [that was owned by Cisco some time ago]) according to the link below (and this is only about hardware compatible with OpenWRT)

    https://openwrt.org/toh/views/toh_extended_all

    And we know from the experience that backdooring something is a risky choice (even for government mandated access - like lawful intercept for the police), someone can discover the backdoor and then anyone would have access.

    I think that bigger problem are ISP: I have for example an LTE router (not TP-Link), branded by one of cell phone operators which was selling them with their Internet plans. They have two versions of firmware - both of them customized with their logo, and both containing hardcoded (and well known) root password... Maybe the manufacturer has issued a firmware version without this vulnerability, but the operator is not providing it...

    Different example - cable modem: end user cannot update it, operator updates it from the network side. End user doesn't know if the modem is patched or even still under active support... And nobody forces ISP to patch end-user equipment

    • Cancel
    • Vote Up 0 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • vmate
    0 vmate 9 months ago in reply to HKPhysicist

    D-link isn't great, especially considering updates and fixing their horrible security, so I would avoid it.

    Mikrotik seems to be the best option if buying new, they are easily available pretty much everywhere, and RouterOS is both very capable and often updated.

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • anniel747
    0 anniel747 9 months ago in reply to JWx

    That is a good reason to bring your own, not the free or location. My wireless phone provider was not happy to be unable to access my phone trough their network as usual with the phones they provide with doctored firmware or software.

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • cstanton
    0 cstanton 9 months ago

    Regardless of the router's manufacturer, it is always worth checking if you can flash it with a custom ROM based on open software.

    For example https://openwrt.org/ , https://dd-wrt.com/ and then also using firewalls such as https://opnsense.org/ , https://www.pfsense.org/ and considering DNS blocking services such as https://pi-hole.net/ 

    It can become cumbersome to maintain, but it gives you a lot more control over what is coming and going on your network.

    • Cancel
    • Vote Up +6 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
  • colporteur
    0 colporteur 9 months ago in reply to cstanton

    Open Source router software solutions have the advantage of many prying eyes making it extremely difficult to insert back doors in the code.

    I worked for an ISP that purchased hardware from a vendor that had a static root level passwords. It took considerable paperwork for me to be authorized to have it. Once provided it was trust that ensured it wouldn't be released. Think, one static root password for a vendors entire product line. I shook my head and logged in.

    • Cancel
    • Vote Up +2 Vote Down
    • Sign in to reply
    • Verify Answer
    • Cancel
>
element14 Community

element14 is the first online community specifically for engineers. Connect with your peers and get expert answers to your questions.

  • Members
  • Learn
  • Technologies
  • Challenges & Projects
  • Products
  • Store
  • About Us
  • Feedback & Support
  • FAQs
  • Terms of Use
  • Privacy Policy
  • Legal and Copyright Notices
  • Sitemap
  • Cookies

An Avnet Company © 2025 Premier Farnell Limited. All Rights Reserved.

Premier Farnell Ltd, registered in England and Wales (no 00876412), registered office: Farnell House, Forge Lane, Leeds LS12 2NE.

ICP 备案号 10220084.

Follow element14

  • X
  • Facebook
  • linkedin
  • YouTube