NSA warns on Russia-linked routers
US and allies warned of a Russia-attributed campaign exploiting routers with weak SNMP, default passwords and unpatched firmware.
The NSA attributed a hacking campaign against routers with default passwords or insecure SNMP community strings to Russia-linked actors, in a joint international advisory published with CISA and 18 agencies from 12 countries. The notice focuses on internet-exposed equipment and broadens the scope beyond corporate networks.
The NSA attributed a hacking campaign against routers with default passwords or insecure SNMP community strings to actors linked to Russia, as part of an international warning about the exploitation of these devices. The advisory was issued as joint bulletin AA26-194A, titled "Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting," and is signed by CISA, the NSA and 18 agencies from 12 countries.
What the alert identifies
According to CISA, the scope is global. The warning points to actors linked to FSB Center 16, who are seeking to exploit routers and other internet-exposed devices with SNMP v1 and v2 enabled, default passwords and open management ports. The services mentioned include SNMP 161 and 162, SNMPv3 10161 and 10162, TFTP 69 and Cisco Smart Install 4786.
The US Center 16, according to Infobae, scans the internet for routers that still use default passwords or insecure SNMP community strings, with the goal of identifying vulnerable devices that could be targeted by this campaign.
Recommended technical measures
The official guidance calls for a mandatory migration to SNMPv3 with authentication and encryption. It also recommends disabling SNMP v1 and v2, turning off Cisco Smart Install, applying access control lists so management protocols are only reachable from out-of-band administration networks, and monitoring SNMP Set-Requests directed at sensitive OIDs.
The NSA framed the campaign as part of a broader pattern of using vulnerabilities that are up to 20 years old in routers and network equipment. The agency noted that many devices remain in production with outdated firmware and legacy configurations, a combination that makes initial access to critical networks easier.
Reach beyond large networks
External technical analysis of the advisory says the recommendations also apply to home environments and small homelabs, not just enterprise networks. The reason is the large number of SOHO routers with SNMP enabled and default passwords, which widens the pool of potential victims beyond critical infrastructure.
Independent coverage from the United Kingdom and specialized outlets also said the alert was issued alongside the British NCSC and other allied agencies. That material matches the view that attackers linked to FSB Center 16 are focused on legacy SNMP settings and unpatched firmware as entry points into critical sectors, rather than on a specific zero-day flaw.
Spanish-language technical outlets added that FSB Center 16 is mass-scanning exposed SNMP services with default or trivial passwords to gain initial access, move laterally through the network and reach critical infrastructure systems.
Sources
- UK and Allies Warn on Russian Targeting of Network Devicesstjamesbriefingroom.substack.com· St James Briefing Room
- NSA-Advisory AA26-194A: FSB greift Router via SNMP anlapalutschi.de· lapalutschi.de
- Rusia usa routers inseguros para atacar infraestructuras críticasmentehackers.com· MenteHackers
- Estados Unidos se sumó a la alarma internacional por el hackeo de routers: la NSA atribuye los ataques a Rusiainfobae.com· Infobae
- NSA and Partners Release Guidance on Improving Router Hygiene to Protect Against Russian State-Sponsored Cyber Actorsnsa.gov· NSA
- Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting (AA26-194A)cisa.gov· CISA



