Should you replace your router in 2026? How to check yours
Updated October 8, 2026.
Replace your router if its maker has stopped sending security updates, if it only offers old WEP or WPA encryption, or if it shows signs of tampering. No law makes you replace a working router in 2026. Check the label, the admin page and the maker's support page to see where yours stands.
- The FBI says routers dated 2010 or earlier likely no longer get updates.
- Hijacked home routers power large criminal and state-backed botnets.
- The FCC's 2026 rule doesn't make anyone replace a router they own.
- Your model number and firmware date tell you most of what you need.
Do you have to replace your router in 2026?
No. On March 23, 2026, the FCC added new foreign-made consumer router models to its Covered List. The FCC says the change doesn't affect routers you already own, and stores can keep selling models approved earlier.1
Routers authorized before that date can keep getting software and security updates until at least January 1, 2029, under an FCC waiver.2 For the full story on TP-Link and the rule, read our guide to the TP-Link ban and what to look for next.
The better question is whether your router is still safe to run. That depends on its age, its updates and how it behaves, not on the news.
Seven signs it's time to replace your router
- The maker has declared it end of life. End of life means no more software updates or security patches.3
- It was made in 2010 or earlier. The FBI says routers dated 2010 or earlier likely no longer get updates from their makers.3
- No firmware update in a long time. If the latest version on the maker's site is years old, fixes have probably stopped.
- It only offers WEP or WPA. The FTC calls both outdated and not secure. You want WPA2 or WPA3.4
- It shows signs of tampering. Overheating, dropped connections and settings you didn't change are common signs of infection.3
- You can't see who's connected. If there's no device list, you won't spot a neighbor or a hijacked gadget.
- Everything shares one network. With no guest network, every visitor and smart plug sits next to your laptop.
One sign alone, like a missing guest network, may just mean it's time to plan. The first five are reasons to act now.
The operators could use them to hide their tracks while attacking US networks. The advisory notes that out-of-date devices are more vulnerable, but many in the botnet were likely still supported.5 Updates only help if they get installed.
How to check your router's update support
This takes about 10 minutes. Have your phone ready to snap the label.
- Read the label. The sticker on the bottom or back shows the brand, model number and often a hardware version, like "V2". It usually shows an FCC ID too.
- Open the admin page or app. Note the firmware version and its date, if shown.
- Visit the maker's support page for your exact model and hardware version. Compare your firmware with the latest one.
- Look for an end-of-life notice. Many makers keep a list of models that no longer get updates.
- Check how updates install. Automatic updates are best. If you have to install them by hand, set a reminder.
- Got it from your internet provider? Ask them who made it and how it gets updated.4
Want to know who made it? Search the FCC ID in the FCC's equipment authorization database.6 The first part of the ID shows which company holds the authorization, which is often the factory, not the brand on the box. Our TP-Link guide walks through each step.
How to tell if your router has been hacked
Hacked routers often keep working, so most owners never notice. Criminals rent them out as proxies to hide their tracks. In May 2025, the FBI warned that old routers with remote administration turned on were being taken over this way.3
Watch for these signs:
- The router runs hot to the touch.
- Your connection drops or slows for no clear reason.
- Settings changed and nobody in the house changed them.
- Devices you don't recognize appear in the device list.
If you see them, the FBI's advice is to install any updates, change the admin password, turn off remote management and reboot. If the router is end of life, replace it.3
Keeping your router? Do these five things
Still supported, with no warning signs? Keep it, but tighten it up first.
- Update the firmware and turn on automatic updates if offered.4
- Change the admin password to a long, unique one.3
- Turn off remote management, WPS and UPnP unless you truly need them.4
- Use WPA2 or WPA3 encryption with a strong Wi-Fi password.4
- Move visitors and gadgets to a guest network, away from your computers. Our guide on separating smart home devices explains why.
What to look for in a new router
Before you buy, check these six things. The right column shows how to verify each one.
| Look for | Why it matters | How to check |
|---|---|---|
| Update support | Security fixes stop at end of life | Maker's support page and update policy |
| FCC authorization | New covered models need Conditional Approval | FCC ID search on the box or listing |
| Device approval or alerts | A shared password isn't an open door | Product page or app screenshots |
| Separate networks | Guests and gadgets stay off your laptops | Guest network plus extra networks |
| WPA2 or WPA3 | Older encryption isn't secure | Spec sheet |
| Clear pricing | Some features need a subscription | Pricing page, before checkout |
Count your devices too. Phones, TVs, speakers and plugs add up fast. Our guide on how many devices home Wi-Fi can handle helps you size it, and our router comparison lays out the trade-offs between popular brands.
Where Rio fits. Rio is a $199.99 Wi-Fi 6 router that holds every new device until you approve it, with up to 16 walled-off SecureRooms across 4 Wi-Fi networks. It uses WPA2 Personal, not WPA3. It's designed in USA and manufactured in Taiwan, and its FCC authorization (FCC ID H8NEAI2326) came before the March 2026 change, so it isn't exempt from anything. See how switching works on our replace your router page.
Your old router lets anyone in and never tells you.
Rio holds every new device for your OK and walls gadgets off from your laptops and phones.
See how to switch to RioFrequently asked questions
How often should you replace your router?
There's no fixed schedule. Replace it when the maker stops sending security updates, when it can't use WPA2 or WPA3 encryption, or when it can't keep up with your devices. The FBI says routers dated 2010 or earlier likely no longer get updates from their makers.
Do I have to replace my router because of the FCC rule?
No. The FCC says its March 2026 change doesn't affect routers people already own. It blocks new foreign-made models that lack Conditional Approval. Routers authorized before the change can keep getting software and security updates until at least January 1, 2029, under an FCC waiver.
How do I know if my router has been hacked?
Watch for the signs the FBI lists: a router that runs hot, connections that keep dropping, and settings you didn't change. Unknown devices on your network are another warning. If you see them, update the firmware, change the admin password, turn off remote management and reboot.
How do I find out when my router's support ends?
Find the exact model and hardware version on the label, then check the maker's support page for that model. Look for an end-of-life notice and the date of the latest firmware. If your internet provider supplied the router, ask them how it gets updated.
Sources
- Federal Communications Commission, FCC Updates Covered List to Include Foreign-Made Consumer Routers (fact sheet), March 23, 2026. fcc.gov (PDF)
- FCC Office of Engineering and Technology, DA 26-454, waiver extension for software and firmware updates, May 8, 2026. fcc.gov (PDF)
- FBI, Cyber Criminal Proxy Services Exploiting End of Life Routers, May 7, 2025. ic3.gov
- Federal Trade Commission, How To Secure Your Home Wi-Fi Network. ftc.gov
- FBI, NSA and Cyber National Mission Force, People's Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations, September 18, 2024. ic3.gov (PDF)
- FCC, Equipment Authorization Search (FCC ID). fcc.gov
- Microsoft Threat Intelligence, Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network, October 31, 2024. microsoft.com
