Adam Cady

Why Infrastructure Devices Are Increasingly Targeted by Attackers
Understanding emerging attack surfaces
For years, cybersecurity budgets and attention were built around a simple assumption: attackers go after laptops, servers, and applications. Routers, console servers, and other infrastructure devices sat quietly in the background, assumed to be too obscure or too low-value to matter. That assumption no longer holds.
Forescout's 2026 Riskiest Connected Devices report found that network infrastructure has now surpassed traditional endpoints as the highest-risk category on enterprise networks. Routers alone account for roughly a third of the most critical vulnerabilities organizations face today, averaging nearly 32 vulnerabilities per device. Perhaps more striking: 75% of this year's riskiest device types weren't even on the list two years ago. The attack surface isn't just growing — it's shifting into territory most security teams haven't built defenses for.
Why infrastructure devices make an easy target
Attackers follow the path of least resistance, and infrastructure devices offer several advantages over conventional targets:
They're often under-hardened. Routers, switches, and management interfaces frequently ship with default credentials, run outdated firmware, and fall outside routine patch cycles simply because IT teams treat them as "set it and forget it" hardware.
They enable lateral movement. Once an attacker gains a foothold on an infrastructure device, that device becomes a pivot point — a way to move undetected across a network that's otherwise well-defended at the endpoint level.
They're lightly monitored. Embedded management interfaces typically receive far less security oversight than servers or workstations, giving intruders more room to operate before anyone notices.
A real and growing threat, not a hypothetical one
This isn't a theoretical risk. In 2026, CISA and international partners issued a joint advisory (AA26-113A) warning that China-nexus threat actors are building covert operational networks out of compromised SOHO routers, IoT systems, and edge devices — including firewalls and VPN appliances. These actors specifically favor end-of-life or poorly secured edge devices, using them as rotating "exit nodes" to disguise malicious traffic as legitimate and evade IP-based blocklists. The advisory points to groups like Volt Typhoon and Flax Typhoon, which have used this exact approach to pre-position access inside critical infrastructure — including water and wastewater systems — for future espionage or disruption.
Out-of-band (OOB) management infrastructure deserves particular attention in this conversation. OOB is meant to be the resilient path administrators rely on when the primary network is down or compromised — but if that OOB path itself runs over the public internet, uses third-party or self-attested cryptographic modules, or lacks strong access controls, it becomes exactly the kind of soft target these advisories are warning about.
How secure architecture mitigates the risk
The good news is that the mitigations aren't exotic — they require architectural discipline that many legacy OOB deployments were never designed around:
Remove the device from the public internet entirely. A private, cellular-based management path — rather than one exposed to the open internet — closes off the primary avenue these attackers exploit.
Validate, don't assume, cryptographic strength. First-party FIPS 140-3 validation (as opposed to reliance on a third-party module or a vendor's self-attestation) ensures the cryptography protecting administrative access has actually been tested and certified, not just claimed. This matters more than ever with FIPS 140-2 validations moving to "Historical" status on September 22, 2026 — a deadline that will leave many currently "compliant" deployments unable to claim current validation.
Require strong authentication by default. Built-in two-factor authentication should be a baseline requirement for any device with administrative reach into critical infrastructure, not an optional add-on.
Control power, not just access. The ability to remotely and securely power-cycle equipment — without depending on the primary network — is what turns an OOB deployment from a monitoring tool into a true resilience layer during an incident.
The bottom line
Infrastructure devices are no longer the overlooked corner of the network — they're the frontline. As adversaries increasingly build their operations around exploiting routers, edge devices, and poorly secured management interfaces, the organizations that stay ahead will be the ones that treat OOB and infrastructure management with the same security rigor as their core network.
At Communication Devices, Inc., this is the problem we've built our entire product line to solve: first-party FIPS 140-3 validated, Made-in-USA secure out-of-band management, built on private cellular connectivity rather than internet exposure. Learn more at www.commdevices.com.
Sources:
Share this article
Related Content
United States Office
© 2023 Communication Devices, Inc.