Firmware is low-level software stored in a device’s non-volatile memory that controls its hardware and starts it up – from a laptop’s UEFI/BIOS to the software inside routers, cameras and hard drives.
How firmware works
Firmware sits between the hardware and the operating system. On a PC, UEFI firmware initialises the processor and memory and then hands control to the bootloader. Network devices, IoT gadgets, SSDs, baseboard management controllers (BMC) and even keyboards run their own firmware, often built on embedded Linux or a real-time OS. Vendors ship updates as firmware images that are written (“flashed”) to the chip.
Why firmware matters for security
Code in firmware runs before and below the operating system, so malware there is invisible to most security tools and survives reinstalling the OS or replacing the disk. Examples:
- LoJax (2018) – the first UEFI rootkit found in the wild, attributed to APT28.
- BlackLotus (2023) – a UEFI bootkit sold on criminal forums that could bypass Secure Boot on fully updated Windows systems.
- VPNFilter (2018) – malware that infected more than half a million routers and NAS devices.
Router and VPN appliance firmware is also a frequent target of vulnerabilities exploited for initial access, and compromised update channels turn firmware into a supply chain attack vector. Many IoT devices never receive updates at all, leaving permanent backdoors and weak default passwords.
How to protect firmware
- Install firmware updates for PCs, routers, VPN gateways and IoT devices, and replace devices that are out of support.
- Enable UEFI Secure Boot, TPM-based measured boot and BIOS passwords.
- Accept only cryptographically signed firmware from the vendor.
- Restrict access to management interfaces such as BMC/IPMI.