Routers Named the Riskiest Device Class on Enterprise Networks
Routers and switches now average 32 vulnerabilities per device and account for 34% of the most critical vulnerabilities found on enterprise networks.

Routers and switches have been identified as the riskiest device class on enterprise networks in 2026, averaging 32 vulnerabilities per device and accounting for 34% of the most critical vulnerabilities found.
The concentration makes structural sense. Network infrastructure is long-lived, frequently installed once and revisited only when something breaks, and it sits in the path of everything else — so a compromise there is unusually valuable to an attacker. It is also the equipment most likely to be running firmware several versions behind, because updating it means planned downtime for every service behind it.
IP cameras and network video recorders remain the most consistently targeted device class. The common thread with routers is not the technology but the operational pattern: devices installed by one team, owned by nobody in particular afterwards, and never enumerated again. An asset inventory that includes network and physical-security hardware is unglamorous work and it is the precondition for every other control.
Source: Modem Guides