Home/ Blog/ Security news/ Article
Blog · Security news

FCC adds networked robots and inverters to its Covered List. The installed base is still yours to secure.

The FCC added networked power inverters and mobile robots to its Covered List over remote-control risk.

Networked power inverter and wheeled sensor robot linked to a distant control node

A procurement ban is not a security control, and the space between the two is where the risk now sits. In late July 2026, the Federal Communications Commission added two device classes to its Covered List: networked power inverters and advanced mobile robots. New foreign-produced models in those categories lose the authorization they need to be imported or sold in the United States. That is a lever aimed at what gets bought next year. It does nothing for the inverters and robots already wired into networks today, and those are the ones a defender has to answer for.

The distinction matters because the FCC was explicit about it. Devices that already hold an authorization are not pulled from service, and they keep receiving firmware and security updates through January 1, 2029, per the order. So this is a forward-looking market signal, not a recall. The installed base stays exactly where it is: on your network, doing its job, reachable by whatever remote plane the vendor built into it.

What the FCC flagged, and why it fits our beat

Two categories, both defined broadly. A networked power inverter is any system that converts between direct and alternating current and carries components for remote communication, control, sensing, or monitoring. An advanced mobile robot is a machine that moves on its own, carries sensors, talks over a wireless link, and runs software to steer itself. The common thread is not the physical form. It is that each one is a sensor package bolted to a remote command channel.

The evidence the agency cited reads like a threat model. It pointed to research that pulled video from onboard cameras, audio from microphones, and maps of building interiors off household robots. Reporting on the decision tied documented Bluetooth flaws, tracked as CVE-2025-35027, to root-level command execution on several commercial robot models. For inverters, the concern is blunter: remote access that can switch a unit off, drain data from it, or be aimed at grid stability at scale. None of that needs a novel exploit. It needs a device that answers to someone outside your walls.

Device class addedRemote capability the FCC citedWhat it means on your network
Networked power invertersRemote shutdown, data collection, and monitoring of DC/AC conversion; access that could affect grid stabilityA power-conversion unit with an outward-facing control plane, often tied to a vendor cloud, sitting in facilities infrastructure
Advanced mobile robotsAccess to camera and microphone feeds and interior maps; documented Bluetooth flaws (CVE-2025-35027) enabling root command execution on some modelsA mobile sensor that maps your site and answers to an external command channel, usually filed under operations, not IT
Source: FCC Covered List determination, July 2026, with reporting by The Hacker News and Security Affairs.

The Covered List keeps describing the same shape

Step back and the pattern is consistent. The list has named telecommunications gear from Huawei and ZTE, then video-surveillance equipment from Hikvision and Dahua, and now robots and inverters. In each case the FCC's rationale points to the same recurring property: a networked device with a vendor-controlled remote plane the operator cannot fully audit. Each addition is the regulator catching up to a class of hardware that was already deployed and, once reachable, one weak credential away from being conscripted into a botnet.

That lag is the part worth internalizing, and it is not new. We saw the same beat with export controls: policy trails the technical reality by design. By the time a device category lands on the Covered List, the security decision has already reached you, because the risky units are the ones you bought before anyone flagged them. Many also run embedded firmware that ships with known flaws and no clear patch path. The ban shapes next year's procurement. It leaves this year's exposure to whoever owns the asset. For most organizations that is not the security team, which is the problem.

Treat them as untrusted endpoints, starting with the inventory

The first action is boring and it is the one almost nobody has done: put every networked inverter and robot on the asset inventory as a remote-controllable endpoint. These devices hide in plain sight because they are filed under the wrong department. A rooftop solar inverter is "facilities." A warehouse picking robot is "operations." A cleaning robot is a line item on a maintenance contract. None of them show up on the list the security team actually watches, so nobody is monitoring the network link they all carry.

Once they are on the inventory, the rest follows the logic you apply to any device you do not control. Put them on a segment of their own, with no lateral path to systems that matter, so a compromised inverter or robot cannot become a foothold. Watch their outbound traffic and treat the vendor cloud connection as an untrusted channel: baseline where each device normally talks, then alert when it reaches a destination it has never used. That egress and lateral-movement monitoring is the layer that tells you something changed before the vendor's next advisory does, and it is exactly what a managed detection service is built to run.

Patching still applies. The 2029 update window is real, and firmware fixes should be taken as they ship. But a patch closes a specific hole; it does not remove the architectural fact that these devices carry a remote command plane by design. You manage that with segmentation and monitoring, not with a version bump. The FCC has made the buying decision easier for the next cycle. The one in front of you, the fleet already running inside the perimeter, is still yours to secure.

Topics

Frequently asked questions

What did the FCC add to its Covered List in July 2026?

The FCC added two device categories to its Covered List: networked power inverters and advanced mobile robots. New foreign-produced models in those classes lose the equipment authorization needed to be imported, marketed, or sold in the US. Previously authorized devices are not removed and can still receive updates through January 1, 2029.

Does the FCC action remove robots and inverters already in use?

No. The Covered List restriction applies to new equipment authorizations, not to devices already installed. Existing authorized inverters and robots keep operating and can receive firmware and security updates through January 1, 2029, so the security responsibility for that installed base sits with the operator, not the regulation.

Why does the FCC consider networked inverters and robots a security risk?

Both device classes pair sensors with a remote command channel. The FCC cited research showing exposure of camera feeds, microphone audio, and interior maps from household robots, Bluetooth flaws enabling root-level command execution, and inverter remote access that could shut down units or affect grid stability.

How should a defender secure networked robots and power inverters?

Start by adding every networked inverter and robot to the asset inventory as a remote-controllable endpoint, since these devices often sit under facilities or operations rather than IT. Then segment them off flat networks, restrict lateral access, and monitor their outbound and vendor-cloud connections for unexpected destinations.

What is the FCC Covered List?

The FCC Covered List names communications equipment and services judged an unacceptable national-security risk. Products on it cannot receive the equipment authorization required to enter the US market. It has grown from telecommunications gear to video-surveillance equipment and, in July 2026, to robots and power inverters.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.