Huge survey of 6K+ firmware images of devices by 18 vendors including Linksys and Netgear finds no improvement in software security and lax security standards
A survey of more than 6,000 firmware images spanning more than a decade finds no improvement in firmware security and lax security standards …
Context & Ripple Effects
This survey lands at the end of a decade of warnings that went unheeded. Back in 2015, reporting established that firmware is vulnerable because vendors rarely sign or authenticate the software, and a study of 4,000 embedded devices found reused crypto keys exposing millions of devices with fixes promised by only five vendors. In between, researchers disclosed 10 vulnerabilities across 20+ Linksys Smart Wi-Fi routers, forcing an interim security advisory while new firmware was prepared.
The pattern held right up to publication: weeks earlier, testing of ~10,000 firmware images from 500+ Huawei telecom devices found 55% carried at least one vulnerability. What makes this survey notable is scale and verdict — 6,000+ images across 18 vendors spanning more than ten years, concluding there has been no measurable improvement and standards remain lax.
First-order effects
- Linksys and Netgear, both named in the survey and both with recent public vulnerability episodes, now have documented multi-vendor evidence that their firmware practices match an industry-wide failure rather than isolated lapses.
- Buyers of consumer and small-business networking gear get statistical cover for treating current firmware as unsafe by default rather than trusting vendor claims.
Second-order effects
- Vendors that can demonstrate signed firmware and sustained update pipelines gain a procurement differentiator, since the survey removes the excuse that everyone's firmware is equally bad.
- Enterprise and ISP purchasers of CPE equipment face pressure to add firmware-update guarantees to contracts, shifting support costs back onto the 18 surveyed vendors.
Third-order effects
- If a full decade produced no improvement through voluntary effort, the likely correction is external: regulators or liability regimes mandating authenticated firmware and minimum update lifetimes for connected devices.
- Sustained update obligations favor larger vendors with long-term engineering budgets, pushing the low-margin router market toward consolidation around firms that can afford compliance.
The trend: Firmware security in consumer and embedded devices has stagnated for a decade despite repeated large-scale studies, moving the problem from researcher findings toward regulatory mandates for signed, updatable firmware.