Vulnerabilities discovered in Verizon routers leave millions of consumers at risk

Image Credit: Verizon (Image credit: Image Credit: Verizon)

New research from cybersecurity firm Tenable has discovered multiple vulnerabilities in Verizon Fios Quantum Gateway routers.

If exploited, these vulnerabilities would give an attacker complete control over the router and visibility into everything connected to it which quite alarming given the fact that millions of these devices are currently in use in homes across the US.

The rise of smart homes have turned consumer routers into a top target for cybercriminals and the vulnerabilities (CVE-2019-3914, CVE-2019-3915 and CVE-2019-3916) found by Tenable Research enable a number of attack scenarios that extend to smart devices such as home security systems.

Since these systems are connected to the router and can be compromised remotely, an attacker could potentially tamper with their security settings, change firewall settings or remove parental controls. They could even analyze network traffic to further compromise a victim's online accounts, steal bank details and swipe passwords.

Router vulnerabilities

Co-Founder and Chief Technology Officer at Tenable, Renaud Deraison explained how routers have become a virtual entry point for potential attackers, saying:

“Routers are the central hub of every smart home today. They keep us connected to the corners of the internet, secure our homes and, even, remotely unlock doors. However, they also act as a virtual entry point into the very heart of the modern home, controlling not just what goes out, but also who comes in.”

Tenable has informed Verizon of its discovery and the telecom has assured users that firmware version 02.02.00.12 will address these vulnerabilities and that affected devices will be updated remotely.

TechRadar Pro reached out to Tenable and the company's senior research engineer Chris Lyne offered the following advice for Verizon customers, saying:

"A Verizon customer can check their router’s firmware version in a matter of minutes. First, they must log into their router’s web interface. The user is ‘admin’, and the default password is printed on the side of their router. Unless the password has been manually changed, that should log them in. After logging in, click System Monitoring. The firmware version will be displayed. As of now, 02.02.00.13 is the latest version, and it contains the patch. In addition to ensuring they have the updated firmware, other precautions users can take are to disable remote administration on their router. Also, change the router’s administrator password, so it is different from the one on the side of the router."

  • We've also highlighted the best antivirus to help keep your devices protected from the latest cyber threats
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Pro
Branch office chairs next to a TechRadar-branded badge that reads Big Savings.
This office chair deal wins the Amazon Spring Sale for me and it's so good I don't expect it to last
Saily eSIM by Nord Security
"Much more than just an eSIM service" - I spoke to the CEO of Saily about the future of travel and its impact on secure eSIM technology
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
FlexiSpot office furniture next to a TechRadar-branded badge that reads Big Savings.
Upgrade your home office for under $500 in the Amazon Spring Sale: My top picks and biggest savings
Beelink EQi 12 mini PC
I’ve never seen a PC with an Intel Core i3 CPU, 24GB RAM, 500GB SSD and two Gb LAN ports sell for so cheap
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection