The Federal Communications Commission (FCC) has moved to ban imports of all foreign-produced routers over “unacceptable risks to national security.”
A public notice dated March 23 extends the import ban to consumer-grade devices produced outside the US. The move does not impact any previously-purchased consumer-grade routers, the FCC confirmed, with consumers still able to use devices they’ve already acquired.
The FCC contends that foreign-made routers introduce “a supply chain vulnerability that could disrupt the US economy, critical infrastructure, and national defense,” while also posing “a severe cybersecurity risk that could be leveraged to immediately and severely disrupt US critical infrastructure and directly harm US persons.”
FCC Chairman Brendan Carr welcomed the decision, saying: “Following President Trump’s leadership, the FCC will continue [to] do our part in making sure that US cyberspace, critical infrastructure, and supply chains are safe and secure.”
The move sees foreign-produced routers added to what’s known as the "Covered List," a catalogue of communications equipment and services.
Among the items already subject to the list are telecom equipment from both Huawei and ZTE, following prior bans, and cybersecurity and anti-virus software produced by Kaspersky Lab after a ban imposed by President Trump during his first term over alleged ties with state-sponsored espionage programs in Russia.
Foreign-made routers that receive conditional approval from either the Department of Defense (DoD) or the Department of Homeland Security (DHA) are, however, suitable for import.
The sweeping move was made in the wake of cyberattacks like the China-linked Salt Typhoon that hacked major communication networks from the likes of AT&T, Verizon, and Lumen Technologies. Threat actors behind the notorious 2024 attacks are believed to have resurfaced earlier this year, targeting congressional staff email accounts.
The FCC’s ban references Salt Typhoon and other cyberattacks as a catalyst for the decision, contending security gaps in foreign-made routers were exploited to “attack American households, disrupt networks, enable espionage, and facilitate intellectual property theft.”
Comments