Security & Privacy

Protecting eero customers from NatJack

Aug 6, 2026

At eero, security isn't a feature that we add after the fact – it’s built into our architecture, our development process, and our commitment to continuously improving the eero experience and keeping networks secure without our customers having to lift a finger. Today, we are sharing details about an industry-wide wifi router vulnerability known as "NatJack" and the steps we took to protect eero customers before it was publicly disclosed. 

What is NatJack?

Security researchers recently identified a class of vulnerabilities affecting Network Address Translation (NAT), a fundamental networking function used by virtually every router that shares a single internet connection among multiple devices in a home or business. These vulnerabilities affect routers industry-wide, and while most routers are likely vulnerable to NatJack, you are probably not at risk, since NatJack requires an untrusted device to be connected to your network. The security disclosure is available here. We have no evidence that NatJack has been exploited on any eero network and it is not specific to eero. 

The disclosed techniques target inherent properties of NAT that enable a threat actor to manipulate a router’s NAT tracking table and spoof (mimic) internal client devices. NatJack could allow a malicious device already connected to a network to manipulate the router's connection-tracking state, potentially:

  • Causing service disruptions (denial of service) by exhausting the router’s NAT table.

  • Discovering and disclosing internal NAT port information.

  • Taking over a victim client's TCP connection, steering it to an unintended location across the Internet or disrupting the client’s session - fortunately, 95% of all Internet traffic is encrypted and while NatJack can disrupt a session, it cannot decrypt content.

What we did about it

When we became aware of NatJack, our engineering and security teams immediately validated the vulnerabilities, developed and tested multiple hardening measures, and made them available to the entire eero fleet with eeroOS 7.16.1 – all before public disclosure. This software update applies strict connection-state enforcement that blocks unauthorized connection takeover attempts and deploys automatically to all networks.

We also created a new setting in the eero app that allows customers to enable randomized NAT port allocation, which eliminates the predictability of NAT port usage that threat actors depend on and provides additional protection against port-prediction threats. The “NAT port mode” setting is set to “Direct” by default to ensure compatibility with applications that require peer-to-peer networking, such as gaming and voice services, but can be configured as “Randomized” at any time. Learn more here.

Why eero customers don't have to worry

Traditional routers often rely on customers to manually download and install firmware updates, if updates are even available. eero is built differently:

  • Automatic, secure updates: Every eero receives cryptographically signed over-the-air updates with no logins, downloads, or manual action required. Updates are scheduled in your preferred time window to prevent disrupting everyday networking.

  • Proactive security research: eero and Amazon teams continuously test and harden our products and services, and we collaborate with the broader security community through responsible disclosure.

  • A unified OS across our fleet: Our common software platform means fixes are developed and deployed quickly and consistently to every eero, from our newest Wi-Fi 7 models to earlier generations.

eero networks in bridge mode rely on an upstream router for NAT. If your eero network is in bridge mode, check with your router manufacturer for their security update.

Our commitment

We have dedicated teams of experts who work tirelessly to protect our customers from threats before they’re exploited and respond quickly as new vulnerabilities emerge, automatically and transparently. To learn more about how eero keeps customers secure, including how we discovered and patched a different global vulnerability, read our recent post on eero's security approach.

Thank you for trusting eero.

— Ryan Thompson, Chief Technology Officer

P.S. Security researchers can contact our security team via our bug bounty program.