Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

You usually can’t scan a home router with antivirus software the way you scan a PC. Instead, check its firmware, DNS and security settings, connected devices, and logs—and scan the computers and phones connected to it separately. If you find unauthorized changes or credible signs of compromise, update, reset, or replace the router; a reboot alone is not proof that it is clean.

Can a router get a virus?

Routers can be compromised by malware, exploited vulnerabilities, stolen administrator credentials, malicious firmware, or unauthorized changes to their settings. “Virus” is a familiar shorthand, but router threats can include botnet malware, DNS hijacking, and software that turns a router into a proxy for other people’s traffic. These threats may not produce a desktop-style antivirus alert. The FBI has documented router malware that can collect information passing through a device, disrupt traffic, or use an infected router to attack other systems (FBI/IC3 guidance on VPNFilter).

That does not mean every redirect or slow connection points to the router. An infected laptop, malicious browser extension, faulty cabling, Wi-Fi interference, an ISP outage, or an ordinary smart-home device can cause confusing symptoms while the router itself is fine.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Signs that warrant a check

These are indicators, not proof of an infection:

  • DNS server addresses, administrator settings, Wi-Fi details, or firewall rules changed without your knowledge.
  • Websites redirect to unexpected pages, or search results appear hijacked.
  • Your router administrator password stops working, or remote administration is enabled unexpectedly.
  • Unknown port-forwarding rules, accounts, VPN settings, or static routes appear.
  • Devices you cannot identify show up in the router’s client list.
  • The router repeatedly reboots, overheats, or becomes unstable, or your ISP reports suspicious traffic.

Overheating and connectivity problems can also have ordinary causes. The FBI lists symptoms such as instability and unrecognized settings as possible warning signs, not a diagnosis (FBI alert on end-of-life routers).

#1 Best Overall
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

Before you investigate

  1. Do not enter banking or email credentials on a page reached through a suspicious redirect. Use a known-clean device and a trusted route to your accounts.
  2. Record what you find before changing it. Photograph or note DNS, administrator, firewall, and port-forwarding settings. If you suspect a serious incident, save logs and note times before a reset—unless leaving the router online creates an immediate risk.
  3. Use official sources. Download router firmware only from the manufacturer or ISP’s support site, for the exact model and hardware revision. Do not use a link in a pop-up or unsolicited email.
  4. Avoid third-party “router checker” login pages. Do not give router credentials to an online service just because it claims to scan for viruses.
  5. If the router is actively redirecting traffic or exposing sensitive accounts, disconnect it from the Internet after recording essential evidence, then contact your ISP or the manufacturer.

How to check a router for malware

1. Identify the router and its management page

Find the exact manufacturer, model, hardware revision, firmware version, and whether the device is ISP-supplied. Also note whether you have a modem-router gateway, mesh system, separate router, or access point. A home may have more than one device to inspect: for example, a modem-router plus a separate router can create double NAT.

To find the local gateway address, run the appropriate command on a device connected to your network:

  • Windows: run ipconfig and look for Default Gateway.
  • macOS: run route -n get default and look for gateway.
  • Linux: run ip route and look for the address after default via.

Addresses such as 192.168.0.1, 192.168.1.1, and 10.0.0.1 are common, but none is universal. Open the gateway address over your trusted local connection, or use the router’s official app. An ISP-managed gateway or mesh system may require the provider’s app or support team instead of a local web page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Check firmware and support status

  1. Record the installed firmware version in the official router app or management page.
  2. On the manufacturer’s official support page, find the exact model and hardware revision. Compare the installed firmware with the latest available release.
  3. Check whether the manufacturer or ISP still supports the device and provides security updates.
  4. Install an update only when it is intended for your exact model and revision. Enable automatic updates if the manufacturer offers that option.

Firmware updates close known vulnerabilities, but installing an update does not prove that an already-compromised router has been cleaned. If an ISP owns or manages the router, ask the ISP whether it has installed the latest supported firmware. The FBI and Justice Department have advised replacing routers that are end-of-life or no longer receive support (DOJ guidance on DNS hijacking; FBI alert).

3. Verify DNS settings

DNS translates a domain name, such as example.com, into an address used to reach a site. An attacker who changes DNS settings may be able to redirect lookups. Check both the router’s Internet/WAN DNS settings and any DNS settings it distributes to devices through LAN or DHCP settings.

  1. Find out whether DNS was entered manually or supplied automatically by your ISP.
  2. Compare it with the DNS addresses documented by your ISP or with a trusted provider you deliberately chose. A resolver you do not recognize is not automatically malicious: ISPs, VPNs, parental controls, security products, and workplaces may use nonstandard addresses.
  3. Change an address only if you understand why the replacement is appropriate. Record the original setting first; changing DNS can affect VPNs, filtering, and ISP services.
  4. After correcting a setting, save it and check name resolution from a known-clean device.

Useful commands are nslookup example.com or ipconfig /all on Windows, and dig example.com on macOS or Linux. These show network configuration or DNS responses; they do not scan router firmware or prove the router is clean. In April 2026, the DOJ described compromised routers being used in DNS-hijacking operations and advised users to verify DNS resolvers in router settings (DOJ announcement; FBI/IC3 public service announcement).

Rank #2
Sale
TP-Link ER7206, Multi-WAN Professional Wired Gigabit VPN Router
  • 【Flexible Port Configuration】1 Gigabit SFP WAN Port + 1 Gigabit WAN Port + 2 Gigabit WAN/LAN Ports plus1 Gigabit LAN Port. Up to four WAN ports optimize bandwidth usage through one device.
  • 【Increased Network Capacity】Maximum number of associated client devices – 150,000. Maximum number of clients – Up to 700.
  • 【Integrated into Omada SDN】Omada’s Software Defined Networking (SDN) platform integrates network devices including gateways, access points & switches with multiple control options offered – Omada Hardware controller, Omada Software Controller or Omada cloud-based controller(Contact TP-Link for Cloud-Based Controller Plan Details). Standalone mode also applies.
  • 【Cloud Access】Remote Cloud access and Omada app brings centralized cloud management of the whole network from different sites—all controlled from a single interface anywhere, anytime.
  • 【SDN Compatibility】For SDN usage, make sure your devices/controllers are either equipped with or can be upgraded to SDN version. SDN controllers work only with SDN Gateways, Access Points & Switches. Non-SDN controllers work only with non-SDN APs. For devices that are compatible with SDN firmware, please visit TP-Link website.

4. Review administrator, Wi-Fi, and network-access settings

Check for unrecognized administrator accounts and unexpected changes to the following:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Administrator username and password
  • Wi-Fi network name and password
  • Remote administration or cloud-management access
  • WPS and UPnP
  • Port forwarding, firewall rules, and exposed services
  • VPN settings, dynamic DNS, and static routes
  • Guest networks, DHCP reservations, and IPv6 firewall settings

Change the router administrator password and Wi-Fi password separately: one controls the router’s settings; the other controls access to the network. Use unique passwords rather than reusing email, banking, or other account credentials. The FTC recommends changing default router credentials and distinguishes these two passwords (FTC home Wi-Fi guidance).

For most homes, disable Internet-facing remote administration, WPS, and services you do not use. Consider disabling UPnP if your household does not need automatic port opening. Turning it off can break some game consoles, media servers, cameras, or smart-home applications, so test essential services and configure only the specific access you need. The FTC and FBI both recommend limiting unnecessary remote access and features (FTC; FBI).

5. Inspect connected devices

Look in the router app or management page for a section called Connected Devices, Client List, Wireless Clients, DHCP Clients, or Network Map. Match names and hardware addresses to phones, computers, televisions, printers, cameras, and other devices you own. If a name is unclear, disconnect devices one at a time to see whether an entry disappears. The FTC explains how to review client lists on home networks (FTC connected-device guidance).

An unfamiliar entry is not necessarily an intruder. Phones and laptops can use MAC address randomization, and generic names may belong to a printer, television, or smart-home device. If you confirm an unauthorized client, change the Wi-Fi password, reconnect known devices, and consider putting IoT devices on a guest or separate network.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Review available logs and alerts

If the router provides logs, look for unfamiliar administrator logins, configuration changes, DNS changes, firmware updates, port-forwarding changes, firewall events, unusual outbound connections, or unexplained reboots. Consumer-router logs can be incomplete, difficult to interpret, and erased quickly. A failed login attempt is not proof that someone got in, and inaccurate router time can make timestamps misleading. Small businesses may need more complete, centralized logging and network monitoring; CISA’s guidance covers visibility and hardening for communications infrastructure (CISA guidance).

Rank #3
Omada ER707-M2, Multi-Gigabit VPN Route
  • 【Flexible Port Configuration】1 2.5Gigabit WAN Port + 1 2.5Gigabit WAN/LAN Ports + 4 Gigabit WAN/LAN Port + 1 Gigabit SFP WAN/LAN Port + 1 USB 2.0 Port (Supports USB storage and LTE backup with LTE dongle) provide high-bandwidth aggregation connectivity.
  • 【High-Performace Network Capacity】Maximum number of concurrent sessions – 500,000. Maximum number of clients – 1000+.
  • 【Cloud Access】Remote Cloud access and Omada app brings centralized cloud management of the whole network from different sites—all controlled from a single interface anywhere, anytime.
  • 【Highly Secure VPN】Supports up to 100× LAN-to-LAN IPsec, 66× OpenVPN, 60× L2TP, and 60× PPTP VPN connections.
  • 【5 Years Warranty】Backed by our 5-years warranty and free technical support from 6am to 6pm PST Monday to Fridays

7. Scan connected devices separately

A router settings check cannot remove malware from a computer, phone, NAS, camera, or smart-home hub. Update each device and run its built-in security scan or reputable security software obtained from the vendor’s official site. For devices that do not support antivirus, update their firmware and limit their network access where possible. The FTC recommends using legitimate security software and scanning a device when malware is suspected (FTC malware guidance).

If only one device is infected, cleaning or resetting the router will not remove that device’s malware. Conversely, scanning a laptop does not inspect router firmware.

What router security tools can—and cannot—do

Some router manufacturers provide security checks, malicious-site blocking, vulnerability alerts, or network monitoring. These features can help spot risks or block future threats, but they are not necessarily forensic scans of the router’s complete firmware and do not guarantee that an existing compromise has been removed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • ASUS AiProtection: ASUS describes network protections and a one-tap security scan on compatible routers. Features and availability vary by model and firmware; see the official AiProtection page.
  • NETGEAR Armor: NETGEAR lists threat protection and vulnerability scanning for supported Nighthawk and Orbi devices. Compatibility and terms vary; see NETGEAR Armor.
  • TP-Link HomeShield: Available on compatible routers and Deco systems, with features and tiers varying by model and region. See TP-Link’s HomeShield information.
  • Fing: Can help inventory devices and check network visibility or open ports. It is a monitoring tool, not a universal router-malware remover; see Fing’s feature and plan page.

Check the current compatibility, region, firmware requirements, and any subscription terms for your exact device before relying on a feature. You do not need to buy a security subscription just to inspect DNS, update firmware, change credentials, or reset a router.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if you suspect compromise

Choose a response based on the evidence rather than on one ambiguous symptom.

If suspicion is low

If the only issue is slow Wi-Fi or one strange browser page, scan the affected device, update the router firmware, verify DNS, change the router administrator and Wi-Fi passwords if they are weak or shared, disable remote administration, and review the connected-device list. Check whether the problem returns.

Rank #4
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
  • BUSINESS READY - pfSense+ software updates included for product lifetime. Netgate TAC Lite technical support included. One year hardware warranty included.
  • COMPLETE - Pre-loaded with pfSense+ software to get up and running fast. Simply unbox it and start customizing for your secure edge networking needs. Free help with setup from our expert Technical Assistance Center (TAC) available 24/7/365.
  • POWERFUL - A dual core ARM Cortex-A53 1.2 GHz delivers near gigabit routing of common home iPerf3 traffic and in excess of 650 Mbps of firewall throughput.
  • COMPACT - Low power draw, a compact form factor, and silent operation allow it to run unnoticed when placed on a desktop, wall, or rack.
  • FLEXIBLE - Three (3) 1 GbE switched (WAN/LAN/OPT) ports allow you to configure three separate 1 GbE switched ports for upto a gigabit of bi-directional traffic.

If settings changed or an unauthorized device is present

  1. Disconnect or isolate the suspicious client device.
  2. From a known-clean device, change important account passwords if you may have entered them on a redirected page; enable multifactor authentication where available.
  3. Record relevant settings and logs, then update router firmware from the official source.
  4. Disable remote administration and services you do not need. Change the router and Wi-Fi passwords.
  5. Factory-reset the router and configure it manually rather than immediately restoring an old backup.
  6. Update and scan connected devices, then reconnect them gradually.

If there is credible evidence of hijacking, proxy abuse, credential theft, or repeated reinfection

Disconnect the router from the Internet if safe to do so. Preserve screenshots, logs, timestamps, model and firmware details, and contact your ISP and router manufacturer. Change important passwords from a known-clean device. Replace an unsupported or untrustworthy router rather than relying on a reset. If the incident involves cybercrime or identity theft, report it to the appropriate authorities, including the FBI’s Internet Crime Complaint Center in the United States.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FBI has warned that some router malware may persist or that a reboot may not remove the underlying compromise (FBI/IC3 VPNFilter guidance; FBI residential-proxy alert). A reset is stronger than a reboot, but no generic procedure guarantees removal in every model or attack scenario.

Factory-reset and rebuild safely

A factory reset usually removes saved settings and can disrupt Internet, phone, mesh, parental-control, or port-forwarding configurations. Check the manufacturer’s instructions for your exact model before starting. If the ISP connection requires PPPoE credentials, VLAN details, or a static IP, obtain those details from the ISP first.

  1. Record essential ISP settings and preserve evidence if a serious incident is suspected.
  2. Use the reset procedure and button-hold duration specified by the manufacturer; do not assume every router resets the same way.
  3. Wait for the router to restart fully. Install the latest official firmware as directed by the manufacturer.
  4. Create a new, unique administrator password and new Wi-Fi name and password.
  5. Use WPA3 Personal if available; otherwise use WPA2 Personal. Avoid WEP and obsolete WPA-only security. The FTC identifies WPA3 as preferred and WPA2 as an acceptable alternative (FTC Wi-Fi guidance).
  6. Disable Internet-facing administration, WPS, and unneeded UPnP or port forwards. Recreate only DNS and network settings you understand and need.
  7. Do not restore an old configuration backup if it may contain changed DNS, administrator, firewall, or port-forwarding settings.
  8. Reconnect devices in groups and check the client list and behavior as you go.

A factory reset may not be sufficient for every advanced or factory-installed compromise. The FBI cautions that some malicious connected devices may not be reliably cleaned by a reset alone (FBI alert).

When replacing the router makes more sense

Replacement is the prudent choice if the router is end-of-life, no longer receives security updates, repeatedly becomes compromised after reset, has firmware whose integrity you cannot trust, or lacks current security controls. It may also be necessary if the administrator access cannot be recovered reliably or the ISP cannot provide a supported update. The FBI and DOJ specifically advise replacing end-of-support routers rather than leaving known vulnerabilities unpatched.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When choosing a replacement, check that the manufacturer publishes support information, provides security updates, and offers WPA3 or WPA2, useful firewall controls, and automatic firmware updates. A subscription is not a substitute for a supported router and secure settings.

Quick Recap

SaleBestseller No. 1
Bestseller No. 4
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
Ideal for AI security: Protect your AI workloads and data.
$294.00

Prevent another router compromise

  • Install firmware updates promptly and replace devices that no longer receive them.
  • Use unique administrator and Wi-Fi passwords; protect any router cloud account with multifactor authentication.
  • Use WPA3 Personal where supported, or WPA2 Personal. Do not use WEP.
  • Keep remote administration, WPS, UPnP, and port forwarding off unless you have a specific need.
  • Review connected devices occasionally and remove devices you no longer use.
  • Use a guest or separate network for visitors and, where supported, IoT devices.
  • Update and scan computers and phones; update firmware on cameras, NAS devices, and other connected equipment.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.