VPNFilter: Why the FBI Wants You to Reboot Your Router
On Friday the FBI put out a public service announcement with an unusually simple request: if you own a small office or home office router, turn it off and on again. It sounds like a help desk joke, and since it landed right before Memorial Day weekend, a lot of people probably caught the headline and not much else. So I went back to the official statements to see what they actually say a reboot accomplishes, what it doesn’t, and what else owners are being asked to do.
I’m sticking to the FBI’s announcement, the alerts from US-CERT at the Department of Homeland Security, and advisories the manufacturers posted on their own sites.
What the government said
The FBI’s PSA, alert number I-052518-PSA, dated May 25, says hundreds of thousands of home and office routers and other networked devices around the world have been compromised with malware called VPNFilter. The FBI describes it as able to perform multiple functions, including possible information collection, device exploitation, and blocking network traffic. It can make a router inoperable, and it can potentially collect information passing through the router. The PSA says it targets routers made by several manufacturers and network-attached storage devices from at least one, and that the initial infection vector is currently unknown.
Two days earlier, DHS’s NCCIC posted a short alert that names brands. It lists Linksys, MikroTik, NETGEAR, and TP-Link networking equipment, plus QNAP network-attached storage, as devices known to be affected. It also warns that because the destructive capability can be triggered on one device or many at once, VPNFilter could cut off internet access for hundreds of thousands of users. So this isn’t only about someone watching traffic.
The same day as the PSA, US-CERT published technical alert TA18-145A with recommendations from both DHS and the FBI. It repeats the reboot request and says more about what that reboot does.
What a reboot does, and what it doesn’t
The FBI’s defense section recommends rebooting to temporarily disrupt the malware and to aid the potential identification of infected devices. Notice the word temporarily. Nothing in these announcements says a reboot cleans a router.
The US-CERT alert is more direct about it. It describes VPNFilter as persistent, and it says rebooting removes the non-persistent portions of the malware. In other words, a restart clears out the parts that don’t survive a power cycle, and the part that does survive is still sitting there when the router comes back up. The alert’s guidance for network defenders is to get that persistent piece off the device and put network blocking in place before rebooting, so the rest doesn’t simply come back. A typical household has no way to do that, which is why the lasting fixes are firmware and settings, not the power button.
The second reason in the PSA, helping identify infected devices, means a reboot is worth doing even if you’re fairly sure your router is fine. It costs a couple of minutes without internet.
Update the firmware
Both government notices go past the reboot. The FBI says network devices should be upgraded to the latest available versions of firmware, and US-CERT adds that new firmware often contains patches for vulnerabilities. The manufacturers agree.
Netgear’s advisory, first published May 23, says the malware most likely targets existing vulnerabilities that Netgear has already released firmware fixes for, and tells owners to make sure they’re running the latest firmware. TP-Link’s statement names one model that might be targeted, the TL-R600VPN, and gives the same firmware advice to all of its router owners. QNAP’s advisory NAS-201805-24, published May 24, says the malware reportedly affects some QNAP NAS models running QTS 4.2.6 build 20170628, 4.3.3 build 20170703, or earlier, or still using the default administrator password. It tells owners to update to 4.2.6 build 20170729, 4.3.3 build 20170727, or later, then install Malware Remover 2.2.1 or later and run a full scan. MikroTik’s security page says simply upgrading RouterOS deletes the malware, and the versions it flags are ones released before March 2017.
That’s the uncomfortable pattern. For the vendors who have said so, the fixes already existed, some of them for more than a year. The routers that are in trouble are the ones nobody updated.
If you’ve never updated a router, here’s roughly how it goes. The firmware is the router’s entire software image, operating system and admin page included, and on many models it doesn’t change unless somebody asks. From a computer on your own network, open the router’s admin page in a browser (the address is usually on a label or in the manual), log in with the admin account, and look for a firmware or update section. Some routers can check the manufacturer’s server for you, and Netgear’s advisory links to a how-to for a Check button in its web interface. Others want you to download the file yourself from the support page for your exact model and upload it. If you do, I’d get the file only from the manufacturer’s own site and make sure it matches your model and hardware version. Don’t unplug anything while the update runs, and expect the router to restart when it’s done.
Change the default admin password
Netgear and TP-Link both tell owners to make sure the default admin password has been changed, and QNAP counts a default administrator password among the conditions for affected NAS models. Netgear’s own instructions mention that if you never changed the login, the user name is admin and the password is password. Anyone can read that.
My advice is to pick a long, unique password and keep it in a password manager. On most home routers, this admin password is a separate thing from your Wi-Fi password, so changing one doesn’t change the other.
Turn off remote management
The FBI advises owners to consider disabling remote management settings, and to secure them with strong passwords and encryption if they’re enabled. US-CERT is more specific: management interfaces such as Telnet, SSH, Winbox, and HTTP should be turned off on the WAN side.
A router sits between two networks. The LAN side is your home or office, and the WAN side faces the internet. Normally the admin page only answers on the LAN side, so you have to be on your own network to reach it. Remote management opens it up on the WAN side too, which means anyone on the internet who finds your address can reach the login page. Netgear says remote management is off by default on its routers and can only be turned on in advanced settings, under Advanced, then Remote Management. TP-Link also says it’s off by default and puts the setting under Advanced, System Tools, Administration. It’s worth checking anyway. If you find it on and don’t remember why, I’d turn it off. If you really do need to manage the router from outside, follow the government’s advice to use a strong password and encryption, which in practice means an HTTPS option rather than plain HTTP or Telnet.
What about a factory reset?
Neither the FBI nor US-CERT tells home users to do a factory reset, and none of the manufacturer advisories I’ve mentioned asks for one either. What they ask for is a reboot, current firmware, a changed password, and remote management turned off.
Still, I’d consider one if your device is from one of the named brands, has been running old firmware, and still had a default password or remote management turned on. A reset puts every setting back to defaults, so you’re not trusting a configuration someone else could have changed. If you do it, update the firmware from the manufacturer’s site, then set a new admin password before you set up anything else, and check that remote management is still off. Be honest with yourself about what a reset is for, though. It clears settings, and I haven’t seen an official statement saying it removes this malware. On MikroTik gear, the vendor’s word is that the upgrade does that.
Replace routers that stopped getting updates
Everything above depends on the manufacturer still shipping firmware. Go to the support page for your model and look at the date on the latest release. If it’s years old, or the model is marked as no longer supported, then updating to the latest version may still leave you with holes nobody plans to fix. At that point a new router is a cheaper fix than it sounds, and it’s worth checking how long the maker has kept releasing firmware for its older models before you buy.
Keep checking your manufacturer’s advisory
This is still moving. TP-Link says it’s investigating and will update its post, and NCCIC says it will provide updated information as it becomes available. Bookmark your router maker’s security page and check it again in a week or two.
So yes, reboot the router, because the FBI asked and it helps. Just don’t stop there. The reboot is a pause, and the real fix is firmware from the manufacturer, a password that isn’t the default, and an admin page that doesn’t face the internet.