logo

The Most Common Protocol You’ve Never Heard Of

ID: eeb87606-024c-5dd2-a17a-c4e8ced7dedb

STIX ID: report--eeb87606-024c-5dd2-a17a-c4e8ced7dedb

Feed Name: Censys Blog

Threat Score
65/100

Date Published: 2019-01-30

Date Updated: 2026-04-27

...
...

Censys research highlights that CWMP (TR-069) management interfaces are widely exposed on the Internet (over 20 million hosts) and often run insecure or outdated implementations (notably gSOAP), creating risks of remote configuration abuse and remote code execution; prior incidents (Mirai, Misfortune Cookie/CVE-2014-9222) show exploitation is feasible. The report recommends scanning for exposed CWMP instances, applying firmware updates, restarting modems, and restricting corporate access from vulnerable home networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.