A recent Cybernews study of 25 leading Wi-Fi router brands reveals widespread transparency issues and potential data collection risks, leaving consumers in the dark about their device privacy and security protections.
A Cybernews review of 25 major Wi-Fi router brands has exposed what it describes as a broad transparency problem in the consumer networking market. The study says none of the manufacturers clearly states whether it logs web browsing traffic, instead relying on broad privacy policies that leave customers uncertain about what the hardware itself may collect. According to the researchers, that uncertainty shifts much of the privacy risk on to users.
The study assessed 22 data points across six categories after identifying 44 manufacturers in the United States and narrowing the field to 25 for closer analysis. D-Link came out with the highest risk score at 56, followed by Amazon Eero at 53 and TP-Link, Netgear and Ubiquiti Cloud at 51 each. At the other end of the scale, ASUS recorded the lowest risk score at 34, with Google Nest, GL.iNet and DrayTek Vigor also scoring comparatively better. Cybernews cautioned that a lower score does not prove a router is not collecting data, while a higher score may simply reflect a more detailed disclosure of diagnostic information.
One of the clearest findings concerned DNS requests, which reveal the domains a household’s devices are trying to reach. Every vendor in the sample was marked as not specifying whether it logs DNS queries, and none said how long such records would be retained if they are collected. The researchers also found that many firms apply generic privacy policies designed for broader ecosystems, such as online accounts, mobile apps and smart-home services, rather than publishing router-specific terms.
The report also showed a sharp split between what manufacturers disclose about account data and what they say about network monitoring. Nearly half of the brands confirmed they collect core account details such as email addresses, usernames, phone numbers and postal addresses. By contrast, most did not say whether they inspect local traffic using deep packet inspection. Only Google Nest and Ubiquiti Cloud explicitly denied doing so, while Amazon Eero, MSI Radix and AT&T Turbo Hotspot said they do so only under certain settings. On location data, most brands were again vague: only a small number confirmed collecting nearby Wi-Fi identifiers, and just seven said they gather precise device location. The findings add to a wider body of research showing that consumer routers often struggle not only with privacy disclosure, but also with basic security, with separate studies from German researchers, Fraunhofer and Consumer Reports highlighting firmware flaws, weak protections and patching gaps.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





