A hidden router interface on TCP port 32764
Summary
Eloi Vanderbeken analyses an unknown service in home routers that can read out configurations and execute arbitrary commands with root privileges. The service used TCP port 32764. Devices from several brands were affected.
Ideas
- A proprietary service listens on a fixed TCP port.
- Reverse engineering reconstructs the message format and the available commands.
- The interface reads the router configuration including credentials.
- One command starts arbitrary programs with the highest privileges.
Insights
- Undocumented maintenance access becomes a permanent attack surface.
- Network segmentation limits the damage done by insecure embedded devices.
- Checking firmware needs binary analysis and runtime tests together.
Facts
- The analysis code was published on GitHub.
Recommendations
- Block management access from untrusted networks.
- Replace routers that are no longer maintained or install free firmware.
References
Links to the original source and the Web Archive open in a new tab.