Firmware Updates & Incident Response

Direct firmware update links for common SMB IoT brands + what to do if a device is compromised. Sources: Vendor documentation, CISA, NIST SP 800-61.

Direct links to firmware update pages — check your device monthly
How to update firmware: Log into your device's admin page (usually 192.168.1.1, or check the label on the device), find Settings → Firmware or System → Update, and apply any available updates. Or visit the manufacturer's page below and search your model number. Apply updates during off-hours to minimize disruption.
Hikvision
Cameras & DVRs
Firmware Downloads ↗Security Advisories ↗
Frequent CISA KEV entries — check monthly
Dahua
Cameras & NVRs
Firmware Downloads ↗Security Notices ↗
Multiple critical CVEs — update immediately
Netgear
Routers & Switches
Firmware Downloads ↗Security Advisories ↗
CVE-2017-5521 still widely exploited
TP-Link
Routers & Access Points
Firmware Downloads ↗Security Advisories ↗
CVE-2023-1389 on CISA KEV list
Ubiquiti
Access Points & Routers
UniFi Downloads ↗Release Notes ↗
Change default ubnt/ubnt before deploying
Zyxel
Firewalls & Routers
Firmware Downloads ↗Security Advisories ↗
CVE-2023-28771 on CISA KEV — critical
SonicWall
Firewalls & VPN
Firmware Downloads ↗PSIRT Advisories ↗
CVE-2021-20038 critical — check version now
Fortinet
Firewalls & VPN
Firmware Downloads ↗PSIRT Advisories ↗
CVE-2024-21762 on CISA KEV — patch urgently
Cisco Small Biz
Routers & Switches
Software Downloads ↗Security Advisories ↗
Multiple KEV entries — subscribe to Cisco PSIRT
QNAP
NAS Storage
Firmware Downloads ↗Security Advisories ↗
CVE-2022-27596 critical — update immediately
HP
Printers & MFPs
Firmware Downloads ↗Security Bulletins ↗
Multiple printer CVEs — enable auto-update
Ring / Amazon
Doorbell & Cameras
App & Firmware Updates ↗Security Blog ↗
Enable 2-Step Verification in Ring app now
Can't find your device? Search NIST NVD for your brand and model. Check CISA KEV to see if your device is actively exploited.
Warning signs your IoT device has been compromised
Camera / DVR
Camera moving on its own · credentials changed · footage missing · unknown logins in access log
Router / Network
Unusually slow internet · unknown devices on network · admin password no longer works
Printer / MFP
Print jobs you didn't send · configuration changed · connecting to unknown IP addresses
Smart Lock / Alarm
Door unlocking at unusual times · alarm disarmed remotely · unknown access codes added
General IoT
Device running hot · LED lights behaving strangely · device rebooting unexpectedly
Network-wide
Antivirus alerts on computers · unusual outbound traffic · CISA alert about your device type
Immediate response steps — CISA incident response guidance
Step 1 · Immediately
Disconnect the Suspected Device from Your Network
Unplug the network cable or disable the device's WiFi. Do not power it off — this destroys forensic evidence. Disconnecting stops attacker access while preserving data for investigation. If it's the router, disconnect only as a last resort.
Step 2 · Immediately
Change All Passwords — From a Clean Device
Use your phone or a computer NOT on the compromised network. Change passwords on email, banking, cloud services, and other IoT devices. If the router was compromised, assume all credentials used on that network are known to the attacker.
Step 3 · Within 24 Hours
Factory Reset the Device Before Reconnecting
Hold the reset button 10–30 seconds (check the manual). After reset: immediately change default username and password, update firmware before reconnecting to the internet, and disable remote access features you don't need.
Step 4 · Within 24 Hours
Report to CISA and FBI IC3
Report to CISA (cisa.gov/report) and FBI IC3 (ic3.gov). If customer data was exposed, Pennsylvania data breach law may require notification. Contact Swamp Fox Cyber Defense for guidance on next steps.
Step 5 · Within One Week
Audit All Other IoT Devices on Your Network
If one device was compromised, others sharing the same default password may be too. Check all cameras, routers, and printers. This is exactly what Andrew's free assessment covers — every device, plain-English written report. Book here.
Source: CISA Cyber Guidance for SMBs · NIST SP 800-61 · FBI IC3