Common vulnerabilities include weak default credentials, unpatched firmware, and open ports. Additionally, some routers have outdated encryption protocols or even manufacturer backdoors that hackers can exploit.