HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

ESET Research Shows Inadequate Router Decommissioning Exposes Corporate Data on Secondary Market

ESET’s RSA 2023 research finds that corporate routers sold on secondary markets often retain prior owners' configuration data, creating a potential data‑exposure risk. This highlights the need for auditable hardware sanitization to satisfy control‑assurance requirements.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 eset.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
eset.com

ESET Research Shows Inadequate Router Decommissioning Exposes Corporate Data on Secondary Market

What Happened — ESET’s research presented at RSA 2023 reveals that many corporate routers resold on secondary markets retain configuration data and credentials from prior owners. The study shows that organizations often skip proper sanitization when decommissioning hardware, leaving sensitive information exposed to anyone who acquires the device.

Why It Matters for Trust & Control Assurance

  • The scenario directly tests the control objective of secure hardware decommissioning and asset disposal, a requirement that maps to multiple frameworks (e.g., NIST CSF Identify‑Asset Management, ISO 27001 Asset Management, SOC 2 Security).
  • Continuous control‑assurance programs need verifiable evidence that devices are wiped, logged, and retired according to policy; without it, audit trails are incomplete and risk of downstream data breaches rises.
  • Verisq’s Control Mapping capability can automatically collect and correlate decommissioning evidence across your asset inventory, helping you demonstrate compliance and defend against supply‑chain exposure.

Who Is Affected – Enterprises that own, operate, or outsource network infrastructure (large‑scale corporate networks, MSPs, telecom carriers, and any organization that resells or recycles networking gear).

Recommended Actions

  • Inventory all network devices slated for retirement and verify they are covered by a documented sanitization process.
  • Implement a documented, auditable wipe procedure (firmware reset, credential purge, secure erase of configuration storage).
  • Capture and retain evidence of each decommissioning step in a centralized control‑mapping repository for audit readiness.

Source: ESET press release

Technical Notes – The risk stems from misconfiguration / inadequate sanitization of routers sold on secondary markets. No specific CVE is cited; the exposure is data left in device flash memory, default credentials, and undocumented admin accounts. The attack vector is a third‑party dependency (acquired hardware) that can be leveraged for credential compromise or network pivoting. Source: same as above

📰 Original Source
https://www.eset.com/int/about/newsroom/press-releases/events/eset-presents-new-research-into-corporate-network-vulnerabilities-at-rsa-2023/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →