ESET Research Shows Inadequate Router Decommissioning Exposes Corporate Data on Secondary Market
What Happened — ESET’s research presented at RSA 2023 reveals that many corporate routers resold on secondary markets retain configuration data and credentials from prior owners. The study shows that organizations often skip proper sanitization when decommissioning hardware, leaving sensitive information exposed to anyone who acquires the device.
Why It Matters for Trust & Control Assurance
- The scenario directly tests the control objective of secure hardware decommissioning and asset disposal, a requirement that maps to multiple frameworks (e.g., NIST CSF Identify‑Asset Management, ISO 27001 Asset Management, SOC 2 Security).
- Continuous control‑assurance programs need verifiable evidence that devices are wiped, logged, and retired according to policy; without it, audit trails are incomplete and risk of downstream data breaches rises.
- Verisq’s Control Mapping capability can automatically collect and correlate decommissioning evidence across your asset inventory, helping you demonstrate compliance and defend against supply‑chain exposure.
Who Is Affected – Enterprises that own, operate, or outsource network infrastructure (large‑scale corporate networks, MSPs, telecom carriers, and any organization that resells or recycles networking gear).
Recommended Actions
- Inventory all network devices slated for retirement and verify they are covered by a documented sanitization process.
- Implement a documented, auditable wipe procedure (firmware reset, credential purge, secure erase of configuration storage).
- Capture and retain evidence of each decommissioning step in a centralized control‑mapping repository for audit readiness.
Source: ESET press release
Technical Notes – The risk stems from misconfiguration / inadequate sanitization of routers sold on secondary markets. No specific CVE is cited; the exposure is data left in device flash memory, default credentials, and undocumented admin accounts. The attack vector is a third‑party dependency (acquired hardware) that can be leveraged for credential compromise or network pivoting. Source: same as above