Banned Under NDAA Section 889, but Still on Your xOT Network

Table of Contents

Federally banned devices are running on networks across the country right now, hiding in plain sight, and most have never been found. Every day one stays connected isn’t just a compliance gap. It’s the kind of foothold intelligence agencies say state-sponsored adversaries are already using to sit undetected inside xOT networks, including U.S. critical infrastructure.

National Defense Authorization Act (NDAA) Section 889 prohibits federal agencies and government contractors from procuring or using telecommunications and video surveillance equipment, or any essential component of it, produced by five named companies and their subsidiaries and affiliates: Huawei Technologies, ZTE Corporation, Hytera Communications, Hangzhou Hikvision Digital Technology, and Dahua Technology. The procurement ban took effect August 13, 2019. The use ban, which applies regardless of whether the equipment touches a federal contract, took effect a year later.

That reach is wider than most non-federal organizations assume. Under Section 889(a)(1)(B), any company that wants to hold a federal contract, whether as a prime or as a subcontractor, has to represent that it doesn’t use covered equipment anywhere in its operations, not just on the piece of the business touching that contract. A manufacturer, a data center, a utility, a logistics supplier: if any part of the organization does business with the federal government, the ban follows the entire enterprise network, not just the government-facing piece of it.

That’s the law. Here’s the gap: the label on a device says nothing about the firmware actually running underneath it, and most organizations have no way to check. Firmware, not the badge on the case, is what actually runs the device, handles its network communications, and determines whether it’s a banned platform in disguise.

Here’s the part that should give defenders some comfort: finding these devices doesn’t depend on what the label says. Talk to a device in its own language, instead of trusting the name printed on the case, and it tells you exactly what it is, no matter how well it’s disguised. The wolf can wear all the sheep’s clothing it wants, but it’s still a wolf.

Section 889 also extends beyond its named list. It applies to any entity the Secretary of Defense designates as “owned or controlled by, or otherwise connected to, the government of a covered foreign country.” That clause exists because the drafters understood the obvious workaround: white-label the hardware, OEM the components into a Western-sounding brand, or ship it without a label or under a manufacturer nobody’s heard of, and the compliance problem looks solved on paper.

It isn’t. The same board, the same firmware, and the same risk are still part of the hardware regardless of whose name is on the case. An IP camera, router, IP phone, or radio built on a banned platform doesn’t stop being that platform just because a different company put its logo on it.

This isn’t a theoretical compliance problem. Each of these manufacturers has a documented history of remotely exploitable flaws in exactly the products Section 889 covers, and those flaws don’t go away when the hardware ships under a different name.

Dahua IP cameras, network video recorders, and digital video recorders carry two authentication-bypass vulnerabilities, CVE-2021-33044 and CVE-2021-33045, that let an attacker construct a malicious data packet and skip the device’s login check entirely. The National Vulnerability Database scores these vulnerabilities as 9.8. Both remain on CISA’s Known Exploited Vulnerabilities catalog as of this writing. In August 2026, researchers at Hunt.io disclosed a campaign, codenamed Operation CameraSwarm, that used those two flaws, along with credential attacks and abuse of Dahua’s peer-to-peer relay infrastructure, to compromise more than 14,530 Dahua devices between mid-June and late July 2026, planting a persistent account on at least 1,923 cameras that reportedly survived a factory password reset.

Hikvision IP cameras and network video recorders carry CVE-2021-36260, a command-injection flaw in the web server component that grants an unauthenticated remote attacker a root shell and full control of the device, with a CVSS score of 9.8. Hikvision disclosed it in September 2021, and it has been actively exploited ever since.

Huawei’s HG532 router shipped with a configuration protocol, meant only for the local network, exposed to the open internet. Check Point Research found the flaw, cataloged as CVE-2017-17215, after it had already been weaponized: within days, it was powering Satori, a Mirai botnet variant that recruited hundreds of thousands of devices.

None of these three flaws required the finished product to still carry its original manufacturer’s name. That’s the point defenders have to internalize: the firmware, and whatever it’s vulnerable to, travels with the hardware regardless of the badge on the case. A discovery process that stops at the brand name stops before it’s found anything.

Most asset discovery still leans on MAC address OUI lookups and vendor registries. Both are trivial to spoof or strip, and neither was designed to detect a device that’s been deliberately rebranded. That’s precisely the gap prohibited hardware is built to exploit: it doesn’t announce itself, and most tools have no way to interrogate what’s actually running underneath the brand name.

Closing that gap requires talking to the device itself, in its native protocol, rather than trusting what it claims to be. That’s the difference between a lookup and an identification: one trusts the label, the other verifies the hardware.

In August 2025, the NSA, joined by CISA, the FBI, and international partners, published joint guidance on state-sponsored actors systematically targeting telecommunications, transportation, government, and military infrastructure sectors to build long-term access. The advisory’s core recommendations read like a checklist any OT or IT security team should already have covered: audit network configurations against approved baselines, disable unused ports and protocols, eliminate default administrative credentials, and keep firmware on vendor-supported, patched versions.

The uncomfortable part is how basic that list is, and how hard it remains to execute consistently across a fleet of unmanaged, heterogeneous devices, especially when a meaningful share of that fleet is hardware nobody realized was on the network in the first place.

Enforcement has also kept tightening around the original list rather than replacing it, through a separate but related track. At its July 22, 2026 open meeting, the FCC adopted a Third Report and Order (ET Docket No. 21-232, published in the Federal Register on August 7, 2026) that closes what the agency calls the “component part loophole”: going forward, a device can’t be authorized for the U.S. market if it incorporates a logic-bearing hardware component, such as a chip produced by an entity on the FCC’s Covered List (which includes Huawei, ZTE, Hytera, Hikvision, Dahua, and others), regardless of whose name is on the finished product. That’s a different legal mechanism than Section 889 itself, run through the FCC’s equipment authorization process rather than federal procurement rules, but it closes exactly the gap this piece has been describing.

None of this changes the named list. It changes how much distance a rebrand, an OEM arrangement, or now a shared chipset can actually put between prohibited hardware and a compliant-looking network.

Knowing the law exists doesn’t close the gap. Closing it requires four things working together, not just one:

Discovery that goes past the label. Flagging devices manufactured by Huawei, Dahua, Hikvision, ZTE, and Hytera is the easy part. The harder, more consequential part is catching devices with firmware OEMed from those companies, regardless of who manufactured the device itself, since that’s where most of the exposure actually hides.

Deep visibility once a device is found. Device type, manufacturer, model, IP and MAC addresses, firmware version, active protocols, open ports, and running services like Telnet, SSH, and FTP, enriched with device-specific attributes that matter for risk context, not just inventory.

Risk assessment, not just a compliance flag. Default passwords still in use, outdated or historic firmware, correlation against known CVEs, end-of-life and end-of-support status (now a mandated concern under CISA’s Binding Operational Directive BOD 26-02 on end-of-support edge devices), self-signed or expired certificates, and weak or deprecated ciphers.

Contained, then disabled. Once a high-risk or prohibited device is confirmed, it needs to be isolated or disabled remotely right away, not queued for a future audit cycle.

This is the arc behind Prohibited Device Detection and Response by Dragos: discover devices banned under NDAA Section 889, including those disguised through OEM arrangements or unfamiliar branding; assess the risk each one actually carries; and act on high-risk or prohibited devices remotely, rather than leaving them in place until someone notices.

It’s tempting to file a rebranded IP camera or an unmanaged badge reader under IT hygiene and move on. That’s the wrong bucket. xOT is the standard for defining the full operational environment: any system whose failure or compromise affects a physical process or a high-impact operational outcome, not just the PLCs and historians most people picture when they hear OT. A badge reader gating physical access to a substation. An IP camera system sitting on the same network as the critical infrastructure systems. A two-way radio system carrying safety and operator communications across a plant floor. These may not show up on a traditional OT asset inventory, but any of them can be running banned or unverifiable firmware. xOT is the standard for that reality. The Dragos Platform, including Prohibited Device Detection and Response, is how organizations actually secure it.

On July 28, 2026, CISA, joined by Australia’s, the UK’s, and Canada’s cyber agencies, published joint guidance on isolating vital operational technology systems during an active incident. The guidance exists because state-sponsored groups have already demonstrated years-long, undetected access inside U.S. critical infrastructure. Volt Typhoon, one such group, maintained undetected access to a single U.S. critical infrastructure network for five years, according to a joint advisory from CISA, NSA, and the FBI, positioned not for immediate data theft but for disruption at a moment of its choosing.

A prohibited or disguised device sitting unnoticed on a network is exactly the kind of foothold that supports that kind of pre-positioning: it’s already trusted, already connected, and already invisible to tools that stop checking once they see a familiar brand name. Finding it before an adversary uses it, not after, is the entire point.

That’s not an abstract risk. It’s exactly the kind of blind spot Dragos exists to close, because safeguarding civilization starts with knowing what’s actually connected to the xOT infrastructure it depends on.

Prohibited Device Detection and Response by Dragos discovers devices banned under NDAA Section 889, including those hidden behind OEM arrangements and unfamiliar branding, assesses the risk they pose, and enables defenders to disable them remotely. See how it identifies what’s already on your network that you may not know about.

Schedule a Demo

Player is a Senior Director of Marketing at Dragos, Inc., where he leads product marketing across xOT, Phosphorus, industry verticals, and partners. He sets strategy and drives execution to build category leadership, brand growth, and measurable revenue impact, bringing more than 20 years of senior cybersecurity marketing experience that combines deep technical fluency with a disciplined, customer-first approach.