Popular VPN service ExpressVPN has just released updated software for seven different brands of router. The firmware, which is now available to download from ExpressVPN’s website, is a totally brand new build. This means that, in theory, any previous vulnerabilities found in the original manufacturer firmware should be eliminated.
This includes the Bad Packets vulnerability that affected over 20,000 Linksys routers earlier this month. This issue meant that some Linksys routers were leaking sensitive data about the devices connected to them, including details such as MAC address plus device names and operating systems.
More concerningly, it was also possible to tell whether or not the default admin passwords on the router had been changed. This meant that it was incredibly easy for potentially malicious users to gain access to the device in order to gather personal information or manually change settings.
Another issue that ExpressVPN router users should now be protected from is the infamous KRACK (Key Reinstallation Attack) vulnerability, which came to light at the end of 2017. Security researcher Mathy Vanhoef reported a vulnerability in the WPA2 (WiFi Protected Access) handshake protocol which affected almost every modern WiFi device, making them vulnerable to a range of security flaws.
A spokesperson from ExpressVPN confirmed that all routers, Linksys or otherwise, that were affected by this vulnerability will be protected by the new router software. Other routers that the firmware now protects are the Asus RT-AC87U and the Netgear Nighthawk R7000.
Implementing this new protection does come with a caveat, however, and that is that it may reduce a router’s WiFi stability. ExpressVPN has advised its users that they can turn it off, though, as long as they have patched all the devices that are going to be connected to the router.
Downloading and installing the updated firmware is simple. All users have to do is log in to their ExpressVPN account, select the ‘router’ option and do it all from there. There are setup instructions to follow for those who are a little unsure of what they’re doing, too. The customer support team are also on hand via the 24/7 live chat to answer any potential queries.