
Sky took almost 18 months to fix a software bug with around 6 million routers in the UK, according to security company Pen Test Partners.
The researchers said the vulnerability could have impacted Sky broadband customers who had not changed the default admin password on their router, potentially allowing hackers to control their home networks.
Pen Test Partners first made Sky aware of the vulnerability in May 2020, but it took Sky until October 2021 to update 99 percent of routers, 17 months and 11 days after initial disclosure. In August 2021, the security company asked the BBC to contact Sky to try and force them to accelerate the updates. It decided not to publish the vulnerability to push Sky into faster patching as it would have left millions of Sky customers exposed.
A Sky spokesperson told the BBC that it takes the "safety and security of customers very seriously", adding that an update on such a large scale took time. The spokesperson confirmed that a fix had now been delivered to all Sky-manufactured routers.