When did you last think about your router? Not your Wi-Fi password — the actual box
Think about the last time you actually thought about your router. Not the Wi-Fi password you had to share with a guest, not the speed you're getting on your phone, not the bill you pay every month — the actual physical device sitting on a shelf or table in your house, blinking its lights quietly, doing its job.
For most people, the answer is: never. Your ISP sent a technician, they installed it, and it's been working ever since. As long as the Wi-Fi shows up when you search for it, there's no reason to think about the router at all.
That logic is exactly how home networks get compromised.
What end-of-life actually means — and why it's scary
End-of-life (EOL) for a router is the date when the manufacturer stops releasing firmware updates for that model. Not a gradual slowdown, not a warning notification — just a quiet cutoff where the company decides the product is old enough that it's no longer worth maintaining.
Consumer routers typically reach end-of-life within three to five years of their launch date. Which means that if your router came with your Jio Fiber connection in 2020, there's a real chance it's already past its end-of-life date or will be soon. The same applies to routers from Airtel, BSNL, ACT, and every other ISP in India.
After end-of-life, security researchers continue finding vulnerabilities in that router's firmware — because old firmware code doesn't magically become secure just because the manufacturer stopped caring about it. Hackers study these vulnerabilities, share them in underground forums, and build automated tools to exploit them at scale. But no security patch comes. The vulnerability stays open forever.
Your router is the gateway between the public internet and everything on your home network. If it's compromised, an attacker potentially has access to every device connected to it — your phone, your laptop, your smart TV, your child's tablet, your smart speaker. And in India, where those devices run apps for UPI payments, Gpay, PhonePe, banking, Aadhaar-linked services, and everything else in your financial life — a compromised router isn't a minor inconvenience. It's a direct line to your money.
The especially insidious part: you can't tell
This is what makes router security different from phone or laptop security. When your phone has malware, it sometimes slows down. When your laptop has a problem, you see symptoms. When your router is compromised, it just keeps routing. The internet still works. The Wi-Fi password still connects. Everything looks normal.
The malware running on your compromised router operates silently in the background. It doesn't slow down your connection noticeably. It doesn't trigger an antivirus alert — because your antivirus doesn't scan your router. What it does is monitor your network traffic, potentially intercept data, and in some cases sell access to your home IP address to cybercriminals who use it to conduct attacks or evade detection.
Security researchers report that compromised routers average 32 known vulnerabilities each. They account for roughly one-third of critical vulnerabilities in home and small business networks. And in 2026, routers are the second most actively exploited device category — ahead of even smartphones.
The FBI has specifically warned about routers manufactured in the late 2000s and early 2010s, saying they're at very high risk of compromise because they have years of unpatched vulnerabilities and are still widely in use.
How to check if your router is end-of-life
Step 1: Find your router's model number. It's usually printed on a sticker on the bottom or back of the device. Look for something like "TP-Link Archer C6" or "Jio JioFiber Gateway" with a model number.
Step 2: Go to the manufacturer's website and search for that model number. Look for a section called "Support," "Downloads," or "Firmware Updates."
Step 3: Check when the last firmware update was released. If the last update is more than a year old, be concerned. If the last update is more than two years old, take this seriously. If there's a page that says "End of Life" or "No longer supported," act immediately.
Step 4: If you can't find your router on the manufacturer's website at all, that's a bad sign — it likely means the product is so old it's been removed from support documentation entirely.
For Indian users with ISP-provided routers (which is most of us): the router was likely made by a third-party manufacturer on contract for Jio, Airtel, or BSNL. The support documentation is often harder to find, and ISPs are not always forthcoming about when they stop supporting specific router models. If your ISP-provided router is more than four years old, it's worth calling your ISP and asking specifically whether the device is still receiving security updates.
The AI-powered attack wave making this worse in 2026
Here's the 2026-specific context that elevates this from a chronic background risk to an urgent one. Cybersecurity researchers have documented a significant surge in AI-powered malware that targets IoT devices and routers specifically. Unlike traditional malware that uses fixed attack patterns, AI-driven malware can analyze a router's response signatures, identify which vulnerabilities to try, and adapt its approach when one method doesn't work.
This means that even obscure vulnerabilities in old routers — the kind that might have been too difficult for attackers to exploit manually — are now being successfully exploited by automated AI tools that try thousands of attack variations quickly. The effective attack surface of an end-of-life router in 2026 is significantly larger than it was in 2022.
What to do — the practical priority list for Indian households
Priority 1: Check your router's age and support status using the steps above. This takes ten minutes and is worth doing today.
Priority 2: Change the default admin password on your router. This is the login for your router's settings page — not your Wi-Fi password. Default admin credentials (often "admin/admin" or "admin/password") are well-known to attackers. Go to your router's admin page (usually accessible at 192.168.0.1 or 192.168.1.1 from your browser), find the admin password setting, and change it to something unique.
Priority 3: If your router has an automatic firmware update option, enable it. Not all routers do, and an end-of-life router won't get firmware updates regardless — but if your router is still supported and has auto-update available, turn it on.
Priority 4: Disable remote management if it's enabled. Remote management allows someone to log into your router's admin panel from outside your home network. It's a feature designed for IT administrators managing many routers — it has almost no practical use for a home user, and it's a significant attack vector. Log into your router admin page and turn it off.
Priority 5: If your router is more than five years old, budget for a replacement. New routers in India start around ₹1,500-₹2,000 for basic models and go up from there. A TP-Link or D-Link Wi-Fi 6 router costs ₹3,000-₹5,000 and will be supported for several more years. That's a reasonable investment to protect a network that carries your banking transactions, UPI payments, and personal data.
The ISP-provided router situation in India
There's a specific challenge for Indian users: a significant portion of home routers in India are provided by ISPs as part of their broadband installation. Jio Fiber routers, Airtel routers, ACT routers — most households never bought their own router; they got one with the connection.
ISP-provided routers have a complicated support situation. The ISP contractually controls the firmware, which means even if the router hardware manufacturer releases a security update, your ISP may not push it to your device. Some ISPs push firmware updates automatically; many don't. And when you call customer support to ask whether your router is receiving security updates, the front-line agent often doesn't know.
The practical advice: if your ISP-provided router is more than four years old, ask your ISP to provide a replacement. Many ISPs will upgrade your router if you ask, especially if you're on a current-generation plan. If they won't, consider buying your own Wi-Fi router and connecting it to your ISP's ONT (the fiber terminal box), using the ISP device purely as a modem. A separate consumer router that you own and control gives you better security and update management.
TamilTech's take
The router security problem is one of those slow-moving crises that doesn't feel urgent until it's too late. Nobody's phone explodes when their router is compromised. The damage shows up as a UPI fraud that's hard to trace, or a credential theft that takes weeks to discover. In India, where billions of rupees in digital payments flow through home networks every day, end-of-life routers are a genuinely serious vulnerability in the financial security of ordinary households. Ten minutes checking your router model against its support documentation is worth doing right now. If it's past its end-of-life, put a new router on your next shopping list — it's probably the most cost-effective security upgrade you can make.




Comments (0)
Be the first to comment!