Brand profile · models not graded yet

Is FRITZ!Box Safe?

FRITZ!Box routers come from FRITZ! (formerly AVM), a private Berlin company. Automatic updates, CVE history and ownership, explained.

Last reviewed: October 2026 · ismyroutersafe.com

Ownership & FCC Status
Owner
FRITZ! GmbH (Berlin, Germany, private)
FCC Status
Not on the Covered List; no Conditional Approval; US authorization not publicly confirmed
Ban Status
Not banned. Not named on the FCC Covered List
Manufacturing
Europe (per company; country not stated)
Models graded
Not yet

Security Verdict

FRITZ!Box routers are made by FRITZ! GmbH, formerly AVM, a privately held Berlin company majority owned since 2024 by a European family office. The company says its devices are designed in Berlin and manufactured in Europe. Its public vulnerability record since 2023 is small: one high-severity issue that the company disputes, and nothing on CISA's exploited list. FRITZ!Box installs updates automatically by default and the company keeps a public log of security fixes.

Bottom line: FRITZ!Box has a short vulnerability record and installs updates automatically by default. Leave automatic updates on.

Rio Router
From the team behind this checker
Weighing up AVM FRITZ!? See the router that scores an A on this same method.
  • SecureRooms. Smart devices live apart from your computers.
  • You approve every new device before it joins.
  • Rio VPN built in. First year included.
  • Set up in about 10 minutes from the app.
See Rio Router →
$199.99 · 1 year of VPN included, then $7.99/mo · 30-day returns · 1-year warranty. Rio builds this site, and its router is graded by the same method as every other.

Corporate Ownership Structure

FRITZ! GmbH was renamed from AVM GmbH in August 2025; AVM was founded in Berlin in 1986 and has used the FRITZ! brand since 1995. In July 2024 the founders sold a majority stake to Imker Capital Partners, a Europe-based family office, and kept a minority stake. In 2023 the company had about 890 employees and EUR 580 million in revenue.

Key Risk Factors

One disputed high-severity flaw
CVE-2024-54767 (CVSS 7.5) reported unauthenticated information disclosure on the FRITZ!Box 7530 AX running FRITZ!OS 7.59. The vendor disputes it, saying it could not reproduce the issue.
No fixed end-of-support dates
Since January 2021, AVM no longer publishes fixed end-of-maintenance or end-of-support dates, saying products often receive updates past earlier dates.
Automatic updates on by default
Per AVM help, the default setting notifies of updates and installs all updates automatically.
Public security fix log
FRITZ! lists security fixes by FRITZ!OS version on its security information page, such as an XSS fix in FRITZ!OS 8.02 (January 2025).
No flaws on CISA's exploited list
No AVM or FRITZ! vulnerability is in the CISA Known Exploited Vulnerabilities catalog as of October 2026, and no botnet or state-actor reports were found for 2023 to 2026.

Known CVEs - AVM FRITZ! Routers

The following vulnerabilities from the NIST National Vulnerability Database affect AVM FRITZ! router models. This is a representative sample; the full CVE list may be longer.

CVE-2024-54767 High (CVSS 7.5)
Reported unauthenticated information disclosure on the FRITZ!Box 7530 AX (FRITZ!OS 7.59), disputed by the vendor as not reproducible.

Frequently Asked Questions

FRITZ!Box has a short public vulnerability record since 2023, with one disputed high-severity issue and nothing on CISA's exploited list. It installs updates automatically by default and the company publishes a log of security fixes. Leave automatic updates turned on.

FRITZ! GmbH, a Berlin company that was named AVM until August 2025. AVM was founded in 1986. Its founders sold a majority stake to Imker Capital Partners, a European family office, in 2024 and kept a minority stake. No state links were found.

Yes. Per AVM help, the default setting notifies you of updates and installs all updates automatically. Since 2021 AVM no longer publishes fixed end-of-support dates.

FRITZ! says its products are designed in Berlin and manufactured in Europe. The specific country and factory are not publicly stated.

FRITZ! is not on the FCC Covered List and holds no Conditional Approval. Whether FRITZ!Box is sold or FCC-authorized in the US is not publicly confirmed. Any new model seeking FCC authorization would fall under the March 2026 rule on foreign-produced routers.

Sources

Facts on this page come from these sources (publish date, or the date we checked the page).

CHECK YOUR SPECIFIC MODEL

Get your router's full security report

Check any specific model for CVEs, FCC status, security capabilities, and your personalized action plan.

Check a Router → Top 10 Safe Routers
Most home routers have hidden risks. Rio Router is the only one we rate A. See why →