- Your home network is more exposed than it should be - Your home network is more exposed than it should be. Your work laptop, banking sessions, security cameras, and smart home devices all pass through this router - a flaw here gives an attacker leverage over all of them at once.
- One wrong VLAN tag or firewall rule on this router silently exposes your devices to the open internet - A wrong VLAN tag or a misapplied firewall rule on this router silently exposes your work laptop or your security camera feed to the open internet - with no warning until something goes wrong. Powerful hardware doesn't protect you if a single port is set up wrong.
- A real gap that affects every device sharing this Wi-Fi - It affects every device sharing this Wi-Fi - your work laptop, your phone, your kids' devices, your security cameras. Not the most urgent threat on the page, but a real edge an attacker can use to reach the rest.
- A small gap that still touches every device on this network - A small gap, not an urgent one - but it still touches everything on this network: your work laptop, your phone, your security cameras, and any guest device that joins the Wi-Fi.

This router gets the basics right, but the gaps are significant. The EdgeRouter X is manufactured in China. If any device on your Wi-Fi gets infected - a kid’s tablet, a smart bulb, a guest’s phone - it can reach your work laptop and banking app on the same flat network.
A C grade is not a sign-off. It means there are real, exploitable issues affecting this network every day.
-
Your home network is more exposed than it should be
Your home network is more exposed than it should be. Your work laptop, banking sessions, security cameras, and smart home devices all pass through this router - a flaw here gives an attacker leverage over all of them at once.
Show technical detail
Foreign manufacture - FCC ban applies: The EdgeRouter X is manufactured in China. The FCC foreign manufacture rule applies based on manufacturing origin regardless of brand.
-
One wrong VLAN tag or firewall rule on this router silently exposes your devices to the open internet
A wrong VLAN tag or a misapplied firewall rule on this router silently exposes your work laptop or your security camera feed to the open internet - with no warning until something goes wrong. Powerful hardware doesn't protect you if a single port is set up wrong.
Show technical detail
EdgeOS complexity - hardening required: EdgeOS is powerful but not hardened by default. Management services should be restricted to trusted LAN addresses. Default credentials must be changed immediately.
-
A real gap that affects every device sharing this Wi-Fi
It affects every device sharing this Wi-Fi - your work laptop, your phone, your kids' devices, your security cameras. Not the most urgent threat on the page, but a real edge an attacker can use to reach the rest.
Show technical detail
2021 Ubiquiti insider breach: A Ubiquiti employee was convicted of stealing customer data. Cloud-connected EdgeRouter accounts may have been affected. Change credentials if you haven't since 2021.
-
A small gap that still touches every device on this network
A small gap, not an urgent one - but it still touches everything on this network: your work laptop, your phone, your security cameras, and any guest device that joins the Wi-Fi.
Show technical detail
Disambiguation: ER-X vs TP-Link ER605: 'ER605' can refer to this Ubiquiti EdgeRouter family OR to the TP-Link ER605 - a completely separate device. The TP-Link version carries Chinese ownership and federal investigation risk. Confirm your device brand before acting on this report.
If a new vulnerability is found for your Ubiquiti EdgeRouter X (ER-X), we'll email you. One email per incident. No spam.
